> ## Documentation Index
> Fetch the complete documentation index at: https://docs.monk.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets and configuration

> Add API keys, passwords and settings without putting them in chat

Give your app the API keys, passwords and settings it needs. Values go through forms in the local dashboard. They never pass through the conversation.

## Before you start

* A project Monk has planned or deployed. See [Deploy an existing app](/guides/deploy-existing-app).

## Ask Monk for a secret

```
/monk the api needs a STRIPE_SECRET_KEY
```

A secret form opens in the [local dashboard](/getting-started/local-dashboard). Type the value there, or use the generator for a random password. Don't paste secrets into chat. If you do by accident, rotate the value.

See which secrets exist (names only, never values):

```
/monk which secrets does this project have?
```

Remove one:

```
/monk remove the OLD_API_KEY secret
```

## Where secrets live

| Scope | Stored | Used for |
| - | - | - |
| This workspace, or all workspaces | Your OS keychain on this computer | Local deploys, and as the source for cluster secrets |
| Organization, account, project or environment | Your Monk cluster | Deployed services |

Monk pushes a local secret to the cluster when a deploy needs it, or when you ask:

```
/monk push the Stripe key to the production environment
```

Pushing a secret to a cluster, or adding one there, opens an approval first.

## Change settings

Non-secret settings, such as environment variables, ports and sizes, live in the `MANIFEST`. Ask for the change; your coding agent edits the `MANIFEST` and Monk validates it:

```
/monk set LOG_LEVEL=debug on the api
/monk add FEATURE_NEW_CHECKOUT=true to the frontend
```

## What you review

The change shows up in the next deploy plan in the local dashboard, with the services it affects. Running services pick up new settings when they are redeployed, which happens after you approve.

## What you get

Settings and secrets injected into the services that use them. Connection settings between services (database hosts, URLs, passwords Monk generated) are wired for you.

## Next

* [Add a database](/guides/add-a-database)
* [Preview environments](/guides/preview-environments)
* [Security](/concepts/security)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.