Skip to main content

What is a client secret?

A client secret (vela_cs_...) authenticates all management operations — creating apps, registering schemas, configuring notification rules, rotating API keys. It has full account access and must only be used in server-side code, CI/CD pipelines, and the Vela CLI. Never put a client secret in frontend JavaScript, mobile app bundles, or public repositories.

Format

Generating a client secret

1

Open the dashboard

Log into the Vela dashboard and go to Settings → Client Secrets.
2

Generate

Click Generate New Secret. Give it a label so you can identify it later (e.g. production-ci).
3

Copy immediately

Copy the full value now — it is shown only once. Vela stores only a hashed version internally.
4

Store securely

Add it to your secret manager, CI/CD environment variables, or .env file (which must be in .gitignore).
If you lose a client secret, revoke it and generate a new one — there is no way to retrieve the original value.

Using a client secret

Using in CI/CD

For GitHub Actions, store the secret as a repository secret:
For other platforms:

Zero-downtime rotation

You can have multiple active client secrets simultaneously. Use this to rotate without interruption:
  1. Generate a new secret in the dashboard
  2. Update all services and CI/CD pipelines to use the new secret
  3. Deploy and verify services are healthy
  4. Revoke the old secret

Revoking a client secret

  1. Go to Settings → Client Secrets in the dashboard
  2. Click the delete icon next to the secret
  3. Confirm — revocation is instant and irreversible
Any service using a revoked secret immediately starts receiving 401 Unauthorized. Rotate to a new secret before revoking to avoid downtime.