> ## Documentation Index
> Fetch the complete documentation index at: https://docs.murmur.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# murmur secret mount

> Deliver one of your own secrets to every VM you spawn, as an environment variable or as a file.

Delivers one of your own [secrets](/catalog/user-secret) to every agent VM you spawn. By default the secret arrives as an environment variable named after the secret. It can instead arrive as an environment variable with another name, or as a file in the VM user's home directory.

Mounts belong to your own [user record](/catalog/user), so they apply only to agents you spawn. Store the secret first by piping its value to `murmur secret set --user <LEAF>`, for example `printf '%s' "$VALUE" | murmur secret set --user <LEAF>`. Mounting a secret that is already mounted replaces its delivery.

## Synopsis

```bash theme={null}
murmur secret mount <LEAF> [--env-name NAME | --file PATH [--mode 0600]]
```

## Arguments

| Name | Type | Required | Description |
| - | - | - | - |
| `LEAF` | string | yes | The name of one of your own secrets, as listed by `murmur secret ls --user`. |

## Flags

| Name | Type | Default | Description |
| - | - | - | - |
| `--env-name` | string | `LEAF` | Deliver as an environment variable with this name instead. Reserved platform variables, such as `GH_TOKEN`, `ANTHROPIC_API_KEY`, and `MURMUR_*`, are rejected. |
| `--file` | string | none | Write the secret as a file at this path instead. The path must start with `~/`. |
| `--mode` | string | `0600` | File permissions in octal. Only valid with `--file`. |

`--env-name` and `--file` are different delivery modes. Pass one at most.

## Output

A confirmation line on stderr:

```
Mounted "<LEAF>" as <target>
```

`<target>` is `$<NAME>` for an environment variable. For a file it is the path, followed by the mode in parentheses when you pass `--mode`.

## Examples

### Deliver as an environment variable

```bash theme={null}
murmur secret mount NPM_TOKEN
```

```
Mounted "NPM_TOKEN" as $NPM_TOKEN
```

### Deliver under another variable name

```bash theme={null}
murmur secret mount NPM_TOKEN --env-name NODE_AUTH_TOKEN
```

```
Mounted "NPM_TOKEN" as $NODE_AUTH_TOKEN
```

### Deliver as a file

```bash theme={null}
murmur secret mount GCP_SA_JSON --file '~/.config/gcloud/sa.json'
```

```
Mounted "GCP_SA_JSON" as ~/.config/gcloud/sa.json
```

Quote the path so your shell does not expand `~`.

## Errors

| Code | Meaning | What to do |
| - | - | - |
| none | `--mode is only valid with --file` | Drop `--mode`, or add `--file`. |
| none | `--env-name and --file are different delivery modes; pass one` | Choose one delivery mode. |
| none | ``caller owns no user namespace, so it has no user secrets — sign in as a developer, or use `murmur secret` for tenant secrets`` | Sign in as yourself with [`murmur login`](/cli/login). API keys that are not tied to a person have no user secrets. |
| none | `update your secret mounts: your user record changed twice while writing; try again` | Something else is editing your user record. Re-run the command. |
| `INVALID_ARGUMENT` | `update your secret mounts: ...` | The mount failed validation, for example a reserved `--env-name` or a path that does not start with `~/`. The message names the field. |

## Related

* [`murmur secret unmount`](/cli/secret-unmount): stop delivering a secret
* [`murmur secret mounts`](/cli/secret-mounts): list your mounts
* [`murmur secret set`](/cli/secret-set): store a secret
* [`user-secret`](/catalog/user-secret): catalog resource reference
* [Profiles and secrets](/concepts/secrets): how secrets reach agents
