Share feedback
Answers are generated based on the documentation.

sbx secret set-custom

内容説明Create or update a custom secret
利用方法sbx secret set-custom [flags]

試験的

This command is experimental.

Experimental features are intended for testing and feedback as their functionality or design may change between releases without warning or can be removed entirely in a future release.

Description

Create or update a custom secret for a service not built into sbx.

Custom secrets work via a placeholder: the sandbox sees the placeholder value instead of the real secret. When the sandbox makes an outbound request to the target host, the proxy replaces the placeholder with the real secret in the request headers — the secret never enters the sandbox directly.

--host accepts an exact host, IP address, or wildcard pattern. Repeat --host to cover multiple unrelated domains with one secret. "" matches a single label and "**" matches any number of labels. For example ".example.com" covers "cli.example.com" and "ide.example.com" with one entry.

Custom secrets apply globally by default. Use --sandbox to scope one to a specific sandbox.

Command secrets run from a fresh temporary directory on the host during verification and refresh. The host temporary directory must be absolute and must remain outside writable sandbox mounts. Relative references such as ./helper or cat token no longer resolve against the project or daemon working directory. Use an absolute helper path outside shared workspaces. sbx does not copy helpers, inspect their dependencies, or confine their execution. Helpers and any code or configuration they load must remain outside writable sandbox mounts. Explicit paths into shared workspaces and broad mounts exposing host configuration or the host temporary directory remain unsafe, including mounts added later with sbx mount.

With --cloud, --host takes exact DNS names only (no IP addresses or wildcards) and the proxy sets --header on requests to those hosts instead of substituting the placeholder.

Options

オプションデフォルト内容説明
--commandUse a command's standard output as the secret value
--envSet this env var in the sandbox to the placeholder value
--formatHow the value fills the header, with one %s; default "Bearer %s" when --header is omitted (with --cloud)
--headerHTTP header the proxy sets to the secret on requests to --host; default Authorization (with --cloud)
--hostHost, IP, or wildcard pattern (e.g. *.example.com); repeatable; with --cloud, exact DNS names only
--nameSecret name; default derived from the first --host (with --cloud)
--no-verifySkip checking the --ref or --command source when storing it
--placeholderPlaceholder value; use {rand} for a random suffix (e.g. sk-{rand})
--refUse a 1Password op:// reference or AWS Secrets Manager ARN as the secret source
--refreshSecret refresh policy: on-demand (default) or after a duration
--sandboxScope the secret to one sandbox (default: all sandboxes)
--show-errorShow resolver standard error if the initial check fails (may contain secrets)
-t, --tokenSecret value (less secure: visible in shell history)
--valueSecret value (less secure: visible in shell history)

Global options

オプションデフォルト内容説明
--cloudDispatch to Docker Cloud Sandboxes API instead of local sandboxd (supported by a growing set of verbs — run 'sbx --cloud --help' for the current list)
-D, --debugEnable debug logging

Examples

# Create a global custom secret. A unique placeholder is generated automatically.
# The sandbox env var API_KEY is set to the placeholder value; outbound requests
# to the host have the placeholder replaced with the real secret.
sbx secret set-custom --host api.example.com --env API_KEY --value secret123

# Use a wildcard host to cover multiple subdomains that share one key.
sbx secret set-custom --host '*.coderabbit.ai' --env CODERABBIT_API_KEY --value secret123

# Use multiple --host flags to cover unrelated domains with the same key.
sbx secret set-custom --host api.example.com --host api.other.io --env API_KEY --value secret123

# Scope to a specific sandbox instead of globally.
sbx secret set-custom --sandbox my-sandbox --host api.example.com --env API_KEY --value secret123

# Custom placeholder with {rand} suffix; the CLI prints the generated value.
sbx secret set-custom --host api.example.com --placeholder sk-{rand} --value secret123