Skip to content

Commit d36f82b

Browse files
authored
Merge pull request #11 from simstudioai/docs/run-workflow-secret-masking
docs(run-workflow): explain that {{KEY}} in run output is a redaction
2 parents b2563e4 + c8754f8 commit d36f82b

1 file changed

Lines changed: 15 additions & 0 deletions

File tree

‎skills/run-workflow/SKILL.md‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -92,6 +92,21 @@ Four properties of runs and run records that mislead diagnosis when unknown:
9292
in-workflow logs block reports the same run's cost in credits. Never compare or store the two as
9393
one number.
9494

95+
## `{{KEY}}` in run output is usually a mask, not a failure
96+
97+
Only `workflows runs get` and `logs get` return the masked copy, where a resolved secret is written
98+
back as `{{KEY}}` - or `[REDACTED_SECRET]` when it cannot be pinned to one name. Live run output is
99+
never masked: a plain run and a `--follow` stream hit the same endpoint and both carry real values,
100+
so never quote either back.
101+
102+
So a `{{KEY}}` in a masked log is usually a resolved secret rather than a broken reference - but it
103+
is not proof. An unresolved name survives too: JavaScript and Python leave it literal, shell
104+
resolves it to the empty string, and a secret shorter than 8 characters is never masked at all, so
105+
its `{{KEY}}` is always unresolved. `sim --output json secrets list` proves only that a name exists,
106+
not that it resolved in this run. When a block behaves as though the credential were literal text,
107+
check the spelling there first - but never "fix" a working reference by rewriting it into
108+
`environmentVariables.KEY` or hardcoding a literal.
109+
95110
Report which mode ran, the terminal status, and the relevant output or error. Include the run id when
96111
the selected execution mode returns one; `--follow` streams omit it. Never print profile credentials
97112
or raw secrets from block inputs.

0 commit comments

Comments
 (0)