Skip to main content
Credential injection lets a Sailbox call an API with a key it never sees. You store an API key with Sail, write an egress policy rule that says which HTTPS host gets it, and give the policy to a Sailbox. Code inside sends a normal request with no credential, and Sail adds it on the way out. Nothing on the Sailbox, including an agent running there, can read the key.

Try it

This stores a secret, injects it as a bearer token on requests to httpbin.org, and asks httpbin to echo the request back. Save the policy as demo.json:
demo.json
Then store the secret, save the policy, give it to a Sailbox, and make a request from inside:
Output
The curl inside the Sailbox never saw the token. Only the request that httpbin received included it. The same flow from the SDKs, with a GitHub token:

Secrets

A secret is a named value that belongs to your organization.
Setting a name that already exists replaces its value. The next matching request from any Sailbox whose policy uses it gets the new value. Names start with a letter or digit and may contain letters, digits, _, and -, up to 128 characters. A value is one non-empty line of text up to 64 KiB, with no tabs, line breaks, or other control characters.

Policies

A credential is added by a rule in an egress policy. The rule specifies the host, optionally narrows the requests it applies to, and sets a header or query parameter to ${secrets.NAME}. The reference has the full document format.
  • Only a saved policy may reference a secret, and the secret must exist before the policy is saved. A document passed straight to a Sailbox cannot use one.
  • Use an exact host. A wildcard such as *.example.com sends the credential to every host it matches.
A saved policy can also include an allowlist, so one policy limits a Sailbox to the hosts it needs and adds their credentials. A saved policy’s document cannot be edited. To rotate which hosts get a credential, save a new policy and set it. To rotate the credential itself, set the secret again.

Giving a Sailbox the policy

Give the same saved policy to as many Sailboxes as you like.
A set replaces the Sailbox’s whole policy and applies to connections opened after the call. See Replacing the policy for what already-open connections see.

Where secrets live

Secrets are stored by Sail and added as the request leaves the Sailbox. Nothing inside the Sailbox ever sees the value, and no Sail API returns it: sail secret show and sail secret list print names and timestamps only.
Output
To remove a secret, replace the policy on every Sailbox that uses it, delete every saved policy that names it, then delete the secret. Sail refuses the other orders. sail egress-policy list shows how many Sailboxes use each policy and which secrets it names.

Limitations

Rules apply to HTTPS only and cannot read or change request bodies or responses. The reference lists every limit.