Conversation
🦋 Changeset detectedLatest commit: a90d689 The changes in this PR will be included in the next version bump. This PR includes changesets to release 1 package
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Contributor
There was a problem hiding this comment.
No issues found across 2 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Architecture diagram
sequenceDiagram
participant User
participant CLI as browse CLI
participant Skill as SKILL.md (bundled skill)
participant Browserbase as Browserbase API
participant Env as Environment Variables
participant Fn as Deployed Function
Note over User,Skill: NEW: Project Secrets docs flow
User->>Skill: Read skill docs
Skill-->>User: Secrets commands (0.11.0+)
User->>CLI: browse cloud secrets create KEY --env MY_VAR
CLI->>Env: Read value from MY_VAR
Env-->>CLI: Secret value
CLI->>Browserbase: POST /secrets (encrypted value)
Browserbase-->>CLI: Metadata {id, secretKey}
CLI-->>User: Show metadata (not plaintext)
User->>CLI: browse cloud secrets list --limit 10
CLI->>Browserbase: GET /secrets?limit=10
Browserbase-->>CLI: Page {data, nextCursor}
CLI-->>User: List metadata
alt nextCursor non-null
User->>CLI: browse cloud secrets list --cursor <next-cursor>
CLI->>Browserbase: GET /secrets?cursor=<next-cursor>
Browserbase-->>CLI: Next page
CLI-->>User: Next page metadata
end
Note over User,Browserbase: Function secret attachment flow
User->>CLI: browse functions publish
CLI->>Browserbase: Publish function
Browserbase-->>CLI: function-id
User->>CLI: browse functions secrets attach <function-id> <secret-id>
CLI->>Browserbase: POST /functions/{id}/secrets
Browserbase-->>CLI: Attachment confirmation
User->>CLI: browse functions invoke <function-id> --params '{"url":"..."}'
CLI->>Browserbase: POST /functions/{id}/invoke
Browserbase->>Fn: Run handler with context
Fn->>Fn: Read context.secrets.SERVICE_TOKEN
Fn-->>Browserbase: Result (no secret in output)
Browserbase-->>CLI: Invocation result
CLI-->>User: Result
Note over User,CLI: Cleanup flows
User->>CLI: browse functions secrets detach <function-id> <secret-id>
CLI->>Browserbase: DELETE /functions/{id}/secrets/{secret-id}
Browserbase-->>CLI: Detach confirmation
User->>CLI: browse cloud secrets delete <secret-id>
CLI->>Browserbase: DELETE /secrets/{secret-id}
Browserbase-->>CLI: Delete confirmation
Note over User,CLI: Local dev limitation
User->>CLI: browse functions dev
CLI->>Fn: Run local function
Fn-->>CLI: context.secrets NOT populated
CLI-->>User: 0.11.0 limitation
Note over User,Skill: Input methods
User->>CLI: browse cloud secrets create KEY (no --env)
CLI->>User: Hidden terminal prompt
User->>CLI: Enter secret value
CLI->>Browserbase: POST /secrets (encrypted)
alt Automation with --stdin
User->>CLI: pipe output with --stdin
CLI->>CLI: Preserve whitespace/trailing newlines
CLI->>Browserbase: POST /secrets
end
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bundled skill used by
browse skills showandbrowse skills installomits the secrets commands released in Browse 0.11.0. Document project secret creation, rotation, metadata lookup, cursor pagination, Function attachment, runtime access, and cleanup, including IDs versus names, safe input methods, project enablement, and the local-development limitation.Includes a
browsepatch changeset so the updated skill ships with the next CLI release. Website companion: https://github.com/browserbase/browserbase-website/pull/292Validation:
browse skills showusing the published 0.11.0 CLI with the updated skill in an isolated temporary package, invoked from a different working directory; stdout matches the complete updated file.git diff --checkpass.E2E Test Matrix
Live production checks on 2026-09-24 used released Browse 0.11.0, SDK Functions 1.0.1, synthetic secrets, and public example.com.
functions initwith npm and pnpm, thenpublish index.ts --dry-run.envfunctions publish index.tsfrom both fresh projectsCOMPLETED, one function eachfunctions dev index.tsand local invocationExample Domain; shutdown exit 0context.secretsis absent as documentedcloud secrets createusing--env/--stdin;get; paginatedlistfunctions secrets attachand paginatedlistfunctions invokeandinvoke --check-statusCOMPLETED; returnedExample Domainand matching secret hashes/lengthscloud secrets updatethrough env and stdin, then invokefunctions secrets detach, then invokecloud secrets deletewhile attached, then invokeInitial cloud builds failed because the devbox's private npm proxy URLs were embedded in deployment lockfiles. Using public npm URLs fixed those test artifacts; this was not evidence that the secrets commands or ordinary Functions deployment are broken. Private-registry deployments were not validated.
The shared-core work in Stagehand #2701 / sdk-functions-node #40 remains useful for SDK parity and removing duplicated implementation. These successful single-project flows do not establish full parity or local secrets injection.
Context: https://browserbase.slack.com/archives/C0B2H9K1K7T/p1790204127511459