secrets:. The value is never in the Method file, and it is never sent to Method. From the shipped support-triage example:
missing_secret and the missing names.
Give this computer the values
findlists theKEY=VALUEfiles near this folder and the key names in each, never values. It says which declared secrets each file holds and prints the import command.import FILE NAME...copies the named values from a file that you name. It does not print them.set NAMEopens a private form in your browser (on127.0.0.1) for one value. When$BROWSERis set, that program opens the link.listshows each name and where its value is found: the shell, this computer, or missing. It never shows values.
~/.config/method/secrets.json (mode 0600). A value exported in the shell comes first.
A coding agent that builds a Method runs method secret find, then the method secret import command that it prints, and tells you which file each key came from. It does not ask first: the values stay on this computer and do not go into the chat. If no file holds a key, it asks you to run method secret set NAME.
Key files and the Claude Code plugin
The Method plugin for Claude Code checks eachRead, Grep, and Bash call before it runs (method guard-keys). When the call opens a key file (a .env file, secrets.env, or Method’s secret store), Claude Code asks you first, because the values would go into the chat. A command that runs Method itself, for example method secret import, passes unless it names Method’s secret store: Method reads key files without showing the values. .env.example, .env.sample, and .env.template are not key files.
Rules
- Names use capital letters, digits, and underscores.
PATH,LANG,HOME,USER,TMPDIR, and names that start withMETHOD_are reserved. - A value of this computer’s secrets found in the Method or in one of its files is the error
secret_value.method validatereports it, andmethod publishrefuses the version. The issue never shows the value. See The issue checker. - Secret values are replaced with
[REDACTED]in every run file,checkpoint.jsontoo. - In production, a worker reads declared secrets from its own environment.
method connectlists the names to set where the app runs. See Production runs.