murmur setup when you onboard your credentials. You can also create and update them manually with murmur set.
Fields
The
plaintext_value field is write-only. When you read a user-secret back with murmur get, the response contains name, created_at, and description — never the encrypted value.Name convention
The default authorization rules grant each developer read, create, edit, and list access to user-secrets matching the pattern{provider}/{username}/*. The murmur setup command follows this convention automatically, producing names like:
When creating user-secrets manually, use the same
{provider}/{username}/{NAME} convention so the authorization pattern matches.
Examples
Setting a user-secret via murmur setup
murmur setup creates user-secrets automatically as part of onboarding:
Creating a user-secret manually
Listing your user-secrets
Reading a single user-secret
name, created_at, and description. The encrypted value is stripped.
Deleting a user-secret
How user-secrets reach agents
When you spawn an agent, the system reads your user record, resolves each referenced user-secret name, and includes the encrypted values in the agent’s launch payload. The well-known secret names map to environment variables on the agent VM:Errors
Related
- Profiles and secrets — concept overview of developer profiles and secret scopes
- secret — tenant-wide secrets shared across all developers
murmur set— CLI command for creating and updating catalog resourcesmurmur get— CLI command for reading catalog resourcesmurmur setup— CLI command that creates user-secrets automatically during onboarding- Secrets management — CLI guide for managing tenant and developer secrets
- Encryption — how secrets are encrypted at rest and in transit
- Permissions — default authorization bindings including the
user-secrets-selfgrant