docs(branching): add the list of all valid secrets fields (#41640)

* docs(branching): add the list of all valid secrets fields

* chore(docs): allow Captcha to the rules spelling lints

* docs(branching): make external secret a star field
This commit is contained in:
Andrew Valleteau authored and GitHub committed 2026-01-05 09:28:16 +01:00
1 parent 3336b22451
commit 351ba14d3c
2 files changed
+54 -1

No files matched your search

@@ -154,7 +154,59 @@ secret = "env(SUPABASE_AUTH_EXTERNAL_GITHUB_SECRET)"
<Admonition type="note" label="Secret fields">
The `encrypted:` syntax only works for designated "secret" fields in the configuration (like `secret` in auth providers). Using encrypted values in other fields will not be automatically decrypted and may cause issues. For non-secret fields, use environment variables with the `env()` syntax instead.
The `encrypted:` syntax only works for designated "secret" fields in the configuration. Using encrypted values in other fields will not be automatically decrypted and may cause issues. For non-secret fields, use environment variables with the `env()` syntax instead.
The following fields support the `encrypted:` syntax:
**Studio**
- `studio.openai_api_key`
**Database**
- `db.root_key`
- `db.vault.*` (any key in the vault map)
**Auth - Core Keys**
- `auth.publishable_key`
- `auth.secret_key`
- `auth.jwt_secret`
- `auth.anon_key`
- `auth.service_role_key`
**Auth - Email (SMTP)**
- `auth.email.smtp.pass`
**Auth - Captcha**
- `auth.captcha.secret`
**Auth - Hooks**
- `auth.hook.mfa_verification_attempt.secrets`
- `auth.hook.password_verification_attempt.secrets`
- `auth.hook.custom_access_token.secrets`
- `auth.hook.send_sms.secrets`
- `auth.hook.send_email.secrets`
- `auth.hook.before_user_created.secrets`
**Auth - SMS Providers**
- `auth.sms.twilio.auth_token`
- `auth.sms.twilio_verify.auth_token`
- `auth.sms.messagebird.access_key`
- `auth.sms.textlocal.api_key`
- `auth.sms.vonage.api_secret`
**Auth - External OAuth Providers**
- `auth.external.*.secret`
**Edge Runtime**
- `edge_runtime.secrets.*` (any key in the secrets map)
</Admonition>
+1
View File
@@ -358,6 +358,7 @@ allow_list = [
"gte-small",
"halfvec",
"hCaptcha",
"Captcha",
"https?:\\/\\/\\S+",
"i.e.",
"imgproxy",