Managing Secrets & API Keys Securely with Libsodium Encryption
Learn how Workflood encrypts third-party API keys and credentials using libsodium XChaCha20-Poly1305 with per-workspace Data Encryption Keys (DEKs).
Security Architecture Overview
When custom workflow actions communicate with external services (Slack, Stripe, Postgres, OpenAI, or Clearbit), API tokens must never be hardcoded in script text.
Workflood provides an **Encrypted Secrets Store** for every workspace: 1. Every workspace is provisioned a unique 256-bit **Data Encryption Key (DEK)**. 2. Secrets are encrypted using **libsodium XChaCha20-Poly1305** before writing to the database. 3. Master Key Encryption Key (KEK) is stored strictly in isolated infrastructure environment secrets. 4. Secrets are decrypted strictly inside the ephemeral **gVisor micro-container** memory space during execution and discarded upon completion.
Adding Secrets in the Dashboard
- In your Workflood workspace, navigate to **Settings > API Secrets**.
- Click **Add Secret**.
- Provide a key name (e.g., `SLACK_BOT_TOKEN` or `STRIPE_SECRET_KEY`) and the secret value.
- Click **Encrypt & Save**. Once saved, raw secret values cannot be viewed in plaintext from the UI.
Accessing Secrets in Custom Actions
Secrets are injected into your action runtime via `process.env` (in TypeScript) or `os.environ` (in Python):
export default async function main(input: { dealName: string; amount: number }) {
const slackToken = process.env.SLACK_BOT_TOKEN
if (!slackToken) {
throw new Error('SLACK_BOT_TOKEN secret is not configured')
}
// Post notification to Slack channel
const res = await fetch('https://slack.com/api/chat.postMessage', {
method: 'POST',
headers: {
'Authorization': `Bearer ${slackToken}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({
channel: '#won-deals',
text: `🎉 New Won Deal: *${input.dealName}* valued at *$${input.amount}*!`
})
})
return { posted: res.ok }
}Frequently Asked Questions
Are workspace secrets shared across all actions in a workspace?
Yes. Any secret stored in your workspace is accessible by all actions within that specific workspace, but strictly isolated from other workspaces.
