> ## Documentation Index
> Fetch the complete documentation index at: https://microsanbox-staging-appcypher-sdk-runtime-bootstrap.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets

> Rust secret substitution and placeholder passthrough

Secrets expose a placeholder to the guest and substitute the real value only for an allowed host and enabled request location. A placeholder in any other location is blocked unless the destination is explicitly allowed to receive it unchanged.

```rust theme={null}
use microsandbox::{Sandbox, SecretViolationAction};

let sandbox = Sandbox::builder("worker")
    .secret(|s| s
        .env("GH_TOKEN")
        .value(token)
        .allow("github.com")
        .allow("api.github.com")
        .substitute_in_headers(false)
        .substitute_in_query(false)
        .substitute_in_body(true)
        .allow_passthrough_for("api.anthropic.com")
        .require_tls_identity(true)
        .violation_action(SecretViolationAction::BlockAndTerminate))
    .secret_violation_action(SecretViolationAction::BlockAndLog)
    .create()
    .await?;
```

`allow()` accepts exact hosts and wildcard patterns such as `*.example.com`. Use `allow_any_host_dangerous(true)` only when every destination may receive the real secret.

Substitution defaults to headers enabled, query disabled, and body disabled. Basic authentication follows the header setting. Disabling substitution does not make a placeholder inert: the placeholder is still blocked unless the request host matches `allow_passthrough_for()`.

`SecretViolationAction` has `Block`, `BlockAndLog`, and `BlockAndTerminate`. The per-secret action overrides the sandbox-wide action. Passthrough is a host policy, not a violation action.

See [Secrets](/sandboxes/secrets) for CLI and YAML syntax.
