Add a secret
SetGITHUB_TOKEN in your host environment, then bind it to api.github.com:
$MSB_GITHUB_TOKEN. Default placeholders preserve the environment variable’s spelling; custom placeholders are optional.
Passing a raw value through an SDK persists it in the host-side sandbox configuration. Stopping the sandbox does not remove that stored value. The CLI example stores an environment reference and reads it at sandbox startup; inline credential values are rejected.
Use a secret
Run the request inside the sandbox:GITHUB_TOKEN holds a placeholder. microsandbox substitutes the real token when the request reaches the allowed host.
Request locations
Enable only the locations your API needs. Disabling headers also disables Basic authentication substitution. Once the destination passes the secret’s host and TLS identity checks, placeholders in disabled locations are forwarded unchanged. For example, a request can authenticate with a substituted header while keeping the placeholder in its body. Other destinations need explicit passthrough permission or follow the violation policy.
Enable query substitution
Enable query substitution
Enable query substitution only when the API requires a credential in the URL:
Enable body substitution
Enable body substitution
Enable body substitution only when the API requires a credential in the body:When enabled, body substitution supports fixed-length HTTP/1 bodies up to 16 MiB and chunked HTTP/1 bodies. Larger fixed-length bodies are blocked. Encoded bodies pass through unchanged; HTTP/2 body substitution is unsupported and matching body placeholders are blocked. See body limits.
Violation policy
When a destination is not permitted to receive the credential or the unchanged placeholder, these policies control what happens to the request:
The first three are violation actions. Passthrough is a separate per-secret host rule; unmatched requests still follow the violation action.
Block and log
The default. No additional configuration is needed; to set it explicitly:Block
Reject the request without a violation log:Block and terminate
Stop the sandbox when a violation occurs:Allow placeholders
Allow an additional host to receive the unchanged placeholder where substitution does not apply. Credential-allowed hosts already receive unchanged placeholders in disabled locations after passing the secret’s identity checks. This permission does not grant access to the credential; existing substitution permissions still apply. For example, allow the placeholder to appear in an AI request:Update secrets
Existing values and removals can apply live when supported. Adding a secret or changing its placeholder requires a restart. These examples use a host environment reference and allow a restart if needed: New secrets added throughmodify require TLS identity by default and turn interception on when it is off, the same way secret does at create time. Interception cannot start on a running sandbox, so that change is restart-backed and appears in the plan as tls. Existing secrets that explicitly allow plain-HTTP substitution with require_tls_identity(false) continue to rotate live without enabling interception. Removing every TLS-dependent secret leaves interception on, since it may have been enabled for reasons of its own.
YAML configuration
You can also declare secrets in sandbox YAML. An exact environment reference avoids persisting the resolved value:substitution selects where credentials are inserted; passthrough permits unchanged placeholders on additional hosts. A top-level secret_violation_action sets the sandbox-wide default. See CLI configuration for loading configuration and CLI equivalents.
Security boundary
- Destination checks: Injection checks the allowed host against observed DNS and TLS identity, including the HTTP request authority. A forged hostname or hard-coded IP is not enough.
- TLS: Injection requires intercepted TLS by default. Bypassed TLS cannot be inspected for placeholders or receive injected credentials. See TLS inspection.
- Trusted hosts: Allowed endpoints receive the real value and could return it to the guest. Keep allow lists narrow and include redirect destinations only when trusted. Wildcards include the root domain and its subdomains.
- Network access: Secret rules decide where credentials can be injected; network rules still control connectivity.
- Guest-side signing: A placeholder cannot replace raw credentials used to sign requests inside the guest. Supplying the real value as a plain environment variable exposes it to guest code.