Build secrets
Build secrets are encrypted, workspace-wide special keys that Lovable makes available to your projects only when they are being built. This is useful for things like installing private software packages that require a login before your app can even run.
Anyone on an Enterprise plan who needs to give their projects access to private resources during the build process.
Do this, in order
- 1
Go to your Workspace settings, then 'Build & deploy', and finally 'Build secrets'.
This is where you manage these special keys for your entire workspace.
- 2
Click 'New variable', then type a name for your secret (like 'NPM_TOKEN') and its value.
The name is how your projects will refer to this secret, and the value is the actual key. You can't change the name later, only delete and re-add it.
- 3
Click 'Save changes'.
Your secret is not stored until you save, and its value will be hidden permanently after this step for security.
- 4
If your project needs to install private npm packages, ask Lovable to configure your project by prompting it with something like: "Install our private package @acme/ui-components from GitHub Packages. The auth token is in the PACKAGES_TOKEN build secret."
Lovable will automatically create the necessary configuration file (like an .npmrc) in your project, referencing the build secret you just created.
Paste this into your project
Install our private package @acme/ui-components from GitHub Packages. The auth token is in the PACKAGES_TOKEN build secret.
Words decoded
- Workspace-level environment variables
- These are special pieces of information (like a username or password) that are available to all your projects within your Lovable account, but only during the building process, not when the app is actually running.
- npm token
- A special key that allows your project to securely download and install private software packages from an 'npm registry' (a central storage place for software).
- Design systems
- A collection of reusable components and guidelines that help keep the look and feel of your apps consistent. Sometimes these components are stored in private packages.
- Source maps
- Special files that help developers debug their code by linking the optimized, hard-to-read code that runs in your app back to the original, human-readable code they wrote.
- Runtime
- The period when your application is actively running and serving users, as opposed to when it's being built or set up.
- Registry
- A central online storage place for software packages, like a library for code. 'npm' is a common package manager that uses registries.
Where people get stuck
- Do not use build secrets for keys your app needs when it's actually running; use project secrets for those.
- Remember that build secrets apply to your entire workspace and cannot be customized per project.
- Only workspace owners and admins can add, edit, or delete build secrets.
- You cannot view a secret's value after saving it; if you lose it, you'll need to generate a new one.
- Deleting a secret is permanent and will cause builds to fail if projects still rely on it.
- Build secrets are only available on Enterprise plans.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.