Docs
Reference

Harness secrets

Export secrets into a Harness project.

Export secrets into a Harness project.

The connection

WhatThis provider
VendorHarness
Keyharness-secrets
Availabilityavailable. You can connect it today.
Credential penv holdsharness-key
Values read backno
Activationimmediate

What it moves

DirectionWhat it does
exportWrites names and values from penv into the store.

Harness returns no value once it holds one, so penv can write here and cannot read back.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
apiKeyAPI keysecret, masked here and sealedyesA Harness API key with secret create and edit permissions.

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
accountIdentifierAccount identifiertextyesnoThe accountIdentifier segment of your Harness URL.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
orgIdentifierOrganizationtextyesnoThe organization holding the project.
projectIdentifierProjecttextyesnoSecrets land at this project's scope, beside the ones it already holds.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
core_secret_viewevery directionyesPreview cannot list the project's secrets.
core_secret_editexportyesExport cannot write anything.