Use a secret manager
Secret managers work with applications, Docker Compose services, and standalone databases. Application support includes Git and non-Git deployment methods.
-
Add a supported provider under Keys & Tokens > Integration Tokens.
-
Open the resource and select Environment Variables.
-
Under Secret manager, choose an Integration token. For a Doppler service account, enter Project (required) and Config (required); a service token fixes these values. For Infisical, enter Project ID, Environment slug, and Secret path. For Vault, enter KV v2 mount and Secret path. Source fields save when you leave the field.
-
Select Browse keys, then Add as variable beside a key or Import all keys. To refresh the list, select Reload keys. You can also add a variable manually with this value:
API_KEY={{vault.API_KEY}} -
Deploy or restart the resource.
Always use {{vault.KEY}}, regardless of whether the provider is Doppler, Infisical, or HashiCorp Vault.
Coolify fetches values during deployment or startup. Values are held in memory and passed to the resource; Coolify does not save the fetched values in its database. A missing source or key stops the operation with a deployment error. Resolved secrets are redacted from deployment logs, including command failures.
Refresh a changed secret
Redeploy or restart the resource after changing a provider value. For application build variables, use a deployment rather than restart. Coolify skips build reuse when build-time secret references may have changed, so a deployment resolves current values rather than relying on a previously built image.
Each resource can link one secret-manager source. A Service-level source applies to the whole Compose stack.
If you have not created credentials yet, follow Secret manager credentials.
