TL;DR: Secrets management in Workers follows a layered approach: local
.dev.varsfor development,wrangler secretfor production, and typed environment variables for access. This guide covers the secrets lifecycle, rotation strategies, and security best practices.
Introduction
Every SaaS application uses secrets: API keys, database credentials, encryption keys. Leaked secrets are one of the most common security vulnerabilities. Workers provides a straightforward secrets management system. For a comprehensive overview of securing your SaaS, see our SaaS Security Best Practices guide.
Secrets Management Layers
| Layer | Local Dev | Staging | Production |
|---|---|---|---|
| Storage | .dev.vars | wrangler secret put | Cloudflare Dashboard |
| Access | File system | CLI | Dashboard UI |
| Rotation | Manual | wrangler secret put | Dashboard |
| Audit | None | CLI history | Dashboard audit log |
Setting Secrets
# Local development
echo "STRIPE_SECRET_KEY=sk_test_xxx" >> .dev.vars
# Production
wrangler secret put STRIPE_SECRET_KEY
# Prompts for value securely
# Bulk secrets from .env
wrangler secret bulk .env.production
Type-Safe Secret Access
export const processPaymentFn = createServerFn({ method: 'POST' })
.handler(async ({ context }) => {
const stripeKey = context.env.STRIPE_SECRET_KEY as string
const stripe = new Stripe(stripeKey)
// Process payment...
})
Best Practices
- Never hardcode secrets in source code
- Use
.dev.vars(gitignored) for local development - Rotate secrets every 90 days
- Use different secrets per environment
- Audit secret access regularly
- Never log secret values
Conclusion
Workers secrets management is simple but effective. Use wrangler secret for production, .dev.vars for development, and treat all secrets as typed environment variables in your server functions. For a deeper look at environment variable configuration in TanStack Start, check out our Environment Variables Guide. And for enterprise-grade secret management, see Secrets Management with Vault.