Skip to slide
Chapter 12 · Secrets and Bring-Your-Own-Key
114 / 191

CHAPTER 12 · Secrets and Bring-Your-Own-Key · 6 / 10

Expose status, never secrets

The UI needs to show users whether a credential is configured and where it came from, but must never receive the secret itself. Provide a status endpoint that returns, per credential, whether it exists and its source (user, operator/env, or none), and nothing more. This lets the settings UI display "configured (from environment, read-only)" or "configured (your key, editable)" without ever transmitting a key to the browser. The client learns that and from where, never what.

← → arrow keys work too