Secret registry
A ready-to-run example is available here.
The Secret Registry provides a secure way to handle sensitive data in your agent's workspace. It automatically detects secret references in bash commands, injects them as environment variables when needed, and masks secret values in command outputs to prevent accidental exposure.
Injecting secrets
Use the update_secrets() method to add secrets to your conversation.
Secrets can be provided as static strings or as callable functions that dynamically retrieve values, enabling integration with external secret stores and credential management systems:
from faheemcode.sdk.conversation.secret_source import SecretSource
# Static secret
conversation.update_secrets({"SECRET_TOKEN": "my-secret-token-value"})
# Dynamic secret using SecretSource
class MySecretSource(SecretSource):
def get_value(self) -> str:
return "callable-based-secret"
conversation.update_secrets({"SECRET_FUNCTION_TOKEN": MySecretSource()})
Ready-to-run example
import os
from pydantic import SecretStr
from faheemcode.sdk import (
LLM,
Agent,
Conversation,
)
from faheemcode.sdk.secret import SecretSource
from faheemcode.sdk.tool import Tool
from faheemcode.tools.file_editor import FileEditorTool
from faheemcode.tools.terminal import TerminalTool
# Configure LLM
api_key = os.getenv("LLM_API_KEY")
assert api_key is not None, "LLM_API_KEY environment variable is not set."
model = os.getenv("LLM_MODEL", "anthropic/claude-sonnet-4-5-20250929")
base_url = os.getenv("LLM_BASE_URL")
llm = LLM(
usage_id="agent",
model=model,
base_url=base_url,
api_key=SecretStr(api_key),
)
# Tools
tools = [
Tool(name=TerminalTool.name),
Tool(name=FileEditorTool.name),
]
# Agent
agent = Agent(llm=llm, tools=tools)
conversation = Conversation(agent)
class MySecretSource(SecretSource):
def get_value(self) -> str:
return "callable-based-secret"
conversation.update_secrets(
{"SECRET_TOKEN": "my-secret-token-value", "SECRET_FUNCTION_TOKEN": MySecretSource()}
)
conversation.send_message("just echo $SECRET_TOKEN")
conversation.run()
conversation.send_message("just echo $SECRET_FUNCTION_TOKEN")
conversation.run()
# Report cost
cost = llm.metrics.accumulated_cost
print(f"EXAMPLE_COST: {cost}")
You can run the example code as-is.
Bring your own provider key
export LLM_API_KEY="your-api-key"
export LLM_MODEL="anthropic/claude-sonnet-4-5-20250929" # or openai/gpt-4o, etc.
cd software-agent-sdk
uv run python examples/01_standalone_sdk/12_custom_secrets.py
Faheem Code Cloud key
# https://app.faheemcode.ai/settings/api-keys
export LLM_API_KEY="example-user-api-key"
export LLM_MODEL="faheemcode/claude-sonnet-4-5-20250929"
cd software-agent-sdk
uv run python examples/01_standalone_sdk/12_custom_secrets.py
Next steps
- MCP Integration - Connect to MCP
- Security Analyzer - Add security validation