TL;DR: Browserbase Functions now support Secrets. Store credentials once, attach only the secrets a Function needs, and access them at runtime through context.secrets. You can build Functions that authenticate with third-party APIs, databases, and other services while keeping sensitive values out of your code.

Browser automations become much more useful when they can act across the rest of your stack. A Function might update a CRM after visiting a customer portal, upload a document to cloud storage, or call an internal API after completing a browser workflow.

Until now, those workflows forced you to choose between limiting what your Function could do or finding your own way to pass credentials into every invocation. Secrets in Functions gives you a secure, reusable way to connect Browserbase Functions to the services your workflows depend on.

What are Secrets?

Secrets are sensitive values (like API keys, access tokens, and service credentials) that you can securely store in Browserbase and make available to specific Functions.

Instead of hardcoding a credential in your Function or including it in every request, you store it once and attach it by reference. When that Function runs, the secrets you explicitly attached are available through context.secrets.

import { defineFn } from "@browserbasehq/sdk-functions";

export default defineFn("update-crm", async (context, params) => {
  const accessToken = context.secrets?.CRM_ACCESS_TOKEN;

  const response = await fetch("<https://api.example.com/v1/records>", {
    method: "POST",
    headers: {
      Authorization: `Bearer ${accessToken}`,
      "Content-Type": "application/json",
    },
    body: JSON.stringify(params),
  });

  return response.json();
});

Your Function gets the credentials it needs at runtime, while your source code stays portable and safe to share.

How it works

There are three steps:

  1. Create a secret in your Browserbase project using the API, SDK, or CLI.
  2. Attach it to a Function so only that individual Function can use it. (Although you can attach the same secret to multiple Functions)
  3. Read it at runtime from context.secrets using the key you assigned.

A Function can access only the secrets you choose for it, not every secret in your project. You can list what is attached without retrieving secret values, and detach a secret whenever a Function no longer needs it.

That makes it easier to follow least-privilege practices as your project grows. Each Function receives only the credentials required for it’s job and nothing more.

Build workflows that reach beyond the browser

You can now combine browser automation with the APIs and services you already use:

  • CRM and sales operations: collect information from a portal, then update a customer record
  • Document workflows: retrieve a document in the browser, then send it to cloud storage or an internal system
  • Authenticated agents: let a browser workflow act across third-party tools without embedding credentials in its code
  • Data pipelines: extract structured data from a website and send it to a database or API
  • Notifications: trigger a message or downstream workflow after a browser task completes

Security by default

With Secrets in Functions, secret values stay hidden from management and listing flows. Functions receive only the secrets explicitly attached to them, and those values are made available at runtime rather than stored in your Function code.

Secrets are encrypted before they are seen by Browserbase. We assign your project a public encryption key, you encrypt with our public key, and send that encrypted secret.

This gives you a cleaner security boundary and a simpler operating model. You can rotate a stored credential without rewriting the Function, detach access when it is no longer needed, and keep sensitive values out of repositories and invocation payloads.

Get started

Secrets in Functions is generally available today. Create your first secret, attach it to a Function, and access it at runtime.

Read the Browserbase docs to get started.

Start building with Browserbase

Run headless browsers for your agents and automations at scale. Get started free in minutes.

Sign up for free