Skip to main content

Product · October 7, 2026 · 3 min read

Introducing E2B Secrets

Giulio MicheloniInfrastructure Engineer
E2B Secrets

Your research agent needs to call a search API. Your document-processing workflow needs an external LLM. To do useful work, agents often need access to services that require credentials.

You can pass a secret as an environment variable. But code running inside the sandbox can read it, print it in a log, or send it somewhere else. Sandbox isolation doesn't protect a credential you've placed inside the sandbox.

We built E2B Secrets to help you connect agents to external services while keeping secrets outside the code execution environment. You store a secret with E2B, reference it by name, and configure which HTTPS destination and request headers should receive it.

For us, this is part of making sandboxes useful for real applications. You need agents that can work with your services and data, with control over how they use your credentials.

How it works

Your agent sends an HTTPS request without the real secret. Outside the sandbox, E2B intercepts requests matching your network rules, resolves the stored secret, and inserts its value into the headers you configured before forwarding the request.

You can inject secret values into any HTTP request header you choose.

Let's build: Call Claude from your sandbox

Suppose your sandbox needs Claude to summarize a document. Let's use an Anthropic API key scoped to a single Anthropic workspace.

From your trusted backend, store the key once using the E2B SDK. The SDK connects to E2B's API over HTTPS, using TLS to encrypt the secret in transit between your application and E2B.

import { Secret } from 'e2b'

// Run in your backend, with E2B_API_KEY and ANTHROPIC_API_KEY configured there.
await Secret.create('anthropic-api-key', process.env.ANTHROPIC_API_KEY!)

Then create a sandbox that can reach api.anthropic.com and configure E2B to inject the stored key into the x-api-key header:

import { Sandbox, Secret } from 'e2b'

const sandbox = await Sandbox.create({
  network: {
    allowOut: ({ rules }) => [...rules.keys()],
    denyOut: ({ allTraffic }) => [allTraffic],
    rules: {
      'api.anthropic.com': [{
        transform: {
          headers: {
            'x-api-key': Secret.fill('anthropic-api-key'),
          },
        },
      }],
    },
  },
})

Secret.fill() creates a reference, so the sandbox configuration contains the secret's name rather than its value.

Inside that sandbox, query Claude with curl:

curl --fail-with-body https://api.anthropic.com/v1/messages \
  -H 'content-type: application/json' \
  -H 'anthropic-version: 2023-06-01' \
  -d '{
    "model": "claude-sonnet-5-5",
    "max_tokens": 256,
    "messages": [{
      "role": "user",
      "content": "Summarize this release note in one sentence: Our export service now supports CSV and JSON, and exports can run on a daily schedule."
    }]
  }'

The command contains the prompt, model, and API version. It doesn't need an API key or an x-api-key header. E2B adds that header after the request leaves the sandbox, and Anthropic returns Claude's response to the sandbox.

You can use the same pattern for paid search APIs, other model providers, or your company's internal HTTPS services.

Keep control of your secrets

E2B stores secret values encrypted at rest. The management API is write-only for values: you can create and update a secret, but reads and lists return metadata, never the secret itself.

For request injection, E2B keeps the value outside the sandbox's environment and filesystem. E2B adds it to the configured headers outside the sandbox and forwards the request to the destination over HTTPS.

When you rotate a key, update it from your backend:

await Secret.update('anthropic-api-key', replacementApiKey)

You can reference the same stored secret from multiple sandboxes in your project. Rotate its value once, and subsequent matching requests from those sandboxes use the new value, without restarting sandboxes or changing their network rules. Paused sandboxes also pick up the current value when they resume. Requests that already resolved the previous value can finish using it.

Try it, and help shape what comes next

E2B Secrets is now generally available. Support for Bring Your Own Cloud (BYOC) is coming soon. Contact support@e2b.dev to register your interest in E2B Secrets for BYOC.

We're also working on easier integrations with third-party services and support for delivering secrets and workload tokens directly inside sandboxes, for tools that need credentials in their execution environment. To share feedback on these upcoming capabilities, reach out to support and tell us what you're building.

Get started with the E2B Secrets documentation, or read more about request injection and secret rotation.

Ask AI
Newsletter