Cloudflare WorkersSecretsSecurityEnvironment

Cloudflare Workers Secrets: Secure Storage That Passed Our Security Audit

Production secrets management for Cloudflare Workers. We passed SOC2 audit using Wrangler secrets, Vault integration, and rotation policies.

Alex Chen
Alex Chen
June 1, 20268 min read

TL;DR: Secrets management in Workers follows a layered approach: local .dev.vars for development, wrangler secret for production, and typed environment variables for access. This guide covers the secrets lifecycle, rotation strategies, and security best practices.

Introduction

Every SaaS application uses secrets: API keys, database credentials, encryption keys. Leaked secrets are one of the most common security vulnerabilities. Workers provides a straightforward secrets management system. For a comprehensive overview of securing your SaaS, see our SaaS Security Best Practices guide.

Secrets Management Layers

LayerLocal DevStagingProduction
Storage.dev.varswrangler secret putCloudflare Dashboard
AccessFile systemCLIDashboard UI
RotationManualwrangler secret putDashboard
AuditNoneCLI historyDashboard audit log

Setting Secrets

bash
# Local development
echo "STRIPE_SECRET_KEY=sk_test_xxx" >> .dev.vars

# Production
wrangler secret put STRIPE_SECRET_KEY
# Prompts for value securely

# Bulk secrets from .env
wrangler secret bulk .env.production

Type-Safe Secret Access

tsx
export const processPaymentFn = createServerFn({ method: 'POST' })
  .handler(async ({ context }) => {
    const stripeKey = context.env.STRIPE_SECRET_KEY as string
    const stripe = new Stripe(stripeKey)
    // Process payment...
  })

Best Practices

  • Never hardcode secrets in source code
  • Use .dev.vars (gitignored) for local development
  • Rotate secrets every 90 days
  • Use different secrets per environment
  • Audit secret access regularly
  • Never log secret values

Conclusion

Workers secrets management is simple but effective. Use wrangler secret for production, .dev.vars for development, and treat all secrets as typed environment variables in your server functions. For a deeper look at environment variable configuration in TanStack Start, check out our Environment Variables Guide. And for enterprise-grade secret management, see Secrets Management with Vault.