Search

Laravel Cloud Secrets Manager: Define an API Key Once, Use It Everywhere

If you run more than a couple of Laravel apps, you know the problem. The same Stripe key, Postmark token or OpenAI key gets pasted into production, staging and three client environments. Then it needs rotating and you're hunting through dashboards hoping you didn't miss one.

Also Read: Deploy Next.js & Nuxt on Laravel Cloud With Your Laravel API - News

Laravel Cloud's Secrets Manager, released on 16 July 2026, removes that job.

How it works

  1. Create a secret once at the organisation level.
  2. Link it to as many environments as need it.
  3. At deploy time, Cloud injects it into those environments as an environment variable.

Rotating a key means writing the new value in one place and redeploying the environments that use it. Your code keeps calling env('STRIPE_SECRET') or config('services.stripe.secret') as before.

The security model

This is the interesting part. Secrets are write-only:

  • Your browser encrypts the value before it's sent, so plaintext never reaches Cloud's servers.
  • Once saved, the dashboard never shows the value again.
  • Secrets are decrypted only when a deployment is created.
  • The organisation's key material is protected by AWS Key Management Service (KMS).

So a teammate with dashboard access can link a secret to an environment without ever seeing it. That's useful when contractors or junior developers need to deploy but shouldn't handle production credentials.

Secrets vs plain environment variables

 Environment variablesSecrets
ScopeOne environmentOrganisation-wide, linked where needed
Visible after savingYesNever
RotationEdit each environmentEdit once, redeploy
Best forApp settings (APP_URL, feature flags)API keys, tokens, passwords

Laravel's own deployment guide now recommends storing sensitive values as Secrets rather than plain variables.

Pair it with the other access controls

Secrets Manager is part of a wider push on access control in 2026:

  • Roles and permissions (7 May): basic RBAC on every plan; custom roles, per-app access and a Restricted role on Business and Enterprise.
  • Scoped API tokens (27 August): tokens limited to specific permissions and to one application or environment.
  • Managed database users (3 September): per-person, per-service database logins instead of shared credentials.

Together, they let you give people and AI agents exactly the access they need.

Also Read: Deploy Go, Express & Hono Apps on Laravel Cloud

FAQ

Can I view a secret after saving it in Laravel Cloud? No. Secrets are write-only and never shown again.

How are Laravel Cloud secrets encrypted? In the browser before submission, with organisation keys protected by AWS KMS.

How do I use a secret in my Laravel app? It arrives as a normal environment variable at deploy time, so read it with env() or through your config files.

Related on The Web Tier

Sources: Laravel Cloud changelog: Secrets Manager · Everything we announced at Laracon US 2026 · How to deploy a Laravel app to Cloud

TWT Staff

TWT Staff

Writes about Programming, tech news, discuss programming topics for web developers (and Web designers), and talks about SEO tools and techniques

Your experience on this site will be improved by allowing cookies Cookie Policy