Secrets
Secrets are a safe place to store important keys and passwords for your app, like API keys, so they don't show up in your code or browser. Lovable automatically uses these secrets in your app's backend when it runs.
Anyone building an app that needs to connect to other services or use sensitive information should use this feature.
Do this, in order
- 1
When Lovable asks for a secret in the project chat, carefully read the name of the secret and the explanation.
This helps you understand what the secret is for and where to find the correct value, like 'STRIPE_SECRET_KEY' for Stripe payments.
- 2
Go to the website of the service (e.g., Stripe, OpenAI) and find the API key or credential that matches the secret name Lovable is asking for.
This ensures you provide the correct, valid key from the original service.
- 3
Enter the key into the secure input field Lovable provides in the chat.
This securely stores the key, encrypts it, and makes it available to your app's backend without exposing it.
- 4
If you need to manage secrets manually, go to 'More → Cloud → Secrets' in your project toolbar.
This allows you to add, replace, or delete secrets directly, though their values can never be viewed after saving.
Paste this into your project
Connect [SERVICE_NAME] so clients can [OUTCOME]. Ask me for any API keys you need.
Words decoded
- API keys
- Special codes that act like a password, allowing your app to talk to another service (like Stripe for payments or OpenAI for AI features).
- Edge Functions
- Small pieces of code that run on Lovable's servers, close to your users, handling tasks that shouldn't happen directly in the user's web browser.
- Backend
- The part of your app that runs on a server, handling things like data storage, security, and complex logic, rather than directly in the user's web browser.
- Environment variables
- Named values that can change depending on where your app is running (e.g., development, testing, live). Secrets are a type of secure environment variable.
- VITE_ environment variables
- Special environment variables that start with 'VITE_' and are meant for your app's frontend (the part users see in their browser). These are not secrets and are safe to be public.
Where people get stuck
- Do not paste sensitive API keys directly into the project chat without Lovable prompting you, as it might expose them.
- Do not try to add 'VITE_'-prefixed variables as secrets; they belong in your project's '.env' file.
- Do not add '.env' to your '.gitignore' file, as Lovable needs it for build-time values.
- Remember that once a secret is saved, its value cannot be viewed again; if you lose it, you'll need to generate a new one from the service.
The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.