CHAPTER 12 · Secrets and Bring-Your-Own-Key · 6 / 10
Expose status, never secrets
The UI needs to show users whether a credential is configured and where it came from, but must never receive the secret itself. Provide a status endpoint that returns, per credential, whether it exists and its source (user, operator/env, or none), and nothing more. This lets the settings UI display "configured (from environment, read-only)" or "configured (your key, editable)" without ever transmitting a key to the browser. The client learns that and from where, never what.