Skip to main content
A Method declares each key by name and purpose under secrets:. The value is never in the Method file, and it is never sent to Method. From the shipped support-triage example:
Every script of the Method (run steps, script checks, tools, and observers) gets all declared secrets as environment variables. A missing value stops the run before its first step, with missing_secret and the missing names.

Give this computer the values

  • find lists the KEY=VALUE files near this folder and the key names in each, never values. It says which declared secrets each file holds and prints the import command.
  • import FILE NAME... copies the named values from a file that you name. It does not print them.
  • set NAME opens a private form in your browser (on 127.0.0.1) for one value. When $BROWSER is set, that program opens the link.
  • list shows each name and where its value is found: the shell, this computer, or missing. It never shows values.
Values are kept in ~/.config/method/secrets.json (mode 0600). A value exported in the shell comes first. A coding agent that builds a Method runs method secret find, then the method secret import command that it prints, and tells you which file each key came from. It does not ask first: the values stay on this computer and do not go into the chat. If no file holds a key, it asks you to run method secret set NAME.

Key files and the Claude Code plugin

The Method plugin for Claude Code checks each Read, Grep, and Bash call before it runs (method guard-keys). When the call opens a key file (a .env file, secrets.env, or Method’s secret store), Claude Code asks you first, because the values would go into the chat. A command that runs Method itself, for example method secret import, passes unless it names Method’s secret store: Method reads key files without showing the values. .env.example, .env.sample, and .env.template are not key files.

Rules

  • Names use capital letters, digits, and underscores. PATH, LANG, HOME, USER, TMPDIR, and names that start with METHOD_ are reserved.
  • A value of this computer’s secrets found in the Method or in one of its files is the error secret_value. method validate reports it, and method publish refuses the version. The issue never shows the value. See The issue checker.
  • Secret values are replaced with [REDACTED] in every run file, checkpoint.json too.
  • In production, a worker reads declared secrets from its own environment. method connect lists the names to set where the app runs. See Production runs.