Cofounder Docs
Secrets and Environment Files
Where secrets live: managed app secrets that ship to deploy targets, database secrets, and local environment files.
There are two kinds of secrets in play, and they live in different places.
App secrets are values your deployed app reads at runtime. Local secrets are
what your environment needs to talk to Cofounder — COFOUNDER_API_TOKEN
and friends.
App secrets
cofounder secrets manages the values your company's deployed app reads:
third-party API keys, webhook secrets, anything that would sit in a
production env file.
| MCP | CLI | API |
|---|---|---|
secrets_set | cofounder secrets set KEY | POST /cofounder-cli/v1/secrets |
secrets_list | cofounder secrets list | GET /cofounder-cli/v1/secrets |
secrets_delete | cofounder secrets delete KEY | DELETE /cofounder-cli/v1/secrets/{key} |
secrets set prompts for the value or reads it from --stdin, so it never
ends up in your shell history. secrets list shows key names and metadata
only — values are write-only.
Database secrets
Edge functions on the managed Supabase project have their own store:
| MCP | CLI | API |
|---|---|---|
supabase_secrets_set | cofounder supabase secrets set | POST /cofounder-cli/v1/company/database/secrets |
supabase_secrets_list | cofounder supabase secrets list | GET /cofounder-cli/v1/company/database/secrets |
Local environment files
Local development keeps secrets out of Cofounder entirely — they're for the
app running on your machine. Keep them in the repo's gitignored env file
(.env.local, .env) and never commit them. Anything the deployed app
needs belongs in secrets instead.
CLI environment variables
The variables the CLI itself reads:
| Variable | Controls |
|---|---|
COFOUNDER_API_TOKEN | Bearer token for CLI, API, and MCP clients |
COFOUNDER_COMPANY_ID | Pins the active company for every call |
COFOUNDER_API_URL | API base URL override |
COFOUNDER_CONFIG_DIR | Where the CLI stores credentials (default ~/.cofounder) |
COFOUNDER_CLI_TELEMETRY | Opts a dev-environment CLI into telemetry — reporting cannot be switched off |
Export them in your environment — the CLI never reads repo env files for its own credentials.
Next steps
Running more than one company under this account? Multiple Companies covers the selection model and per-command scoping.