# lizard secrets

Manage a project's or service's secrets (environment variables).

## Usage

```bash
lizard secrets <subcommand> [args] [flags]
```

## Subcommands

### `lizard secrets set <K=V>...`

Set one or more secrets (variadic). Default scope is the service; `--global` targets the project.

| Flag | Description |
|------|-------------|
| `--global` | Project scope |
| `-s, --service <name>` | Service scope |

### `lizard secrets list`

List secrets in scope.

| Flag | Description |
|------|-------------|
| `--show` | Reveal values |
| `--ref` | Show references |

### `lizard secrets delete <K>...`

Delete one or more secrets (variadic).

### `lizard secrets import`

Import a dotenv file from stdin.

## Examples

### Set secrets on the linked service

```bash
lizard secrets set DATABASE_URL=postgres://… LOG_LEVEL=info
lizard secrets set API_KEY=sk_live_… --service api
```

### Set a project-wide secret

```bash
lizard secrets set NODE_ENV=production --global
```

### List and reveal secrets

```bash
lizard secrets list
lizard secrets list --show
```

### Delete secrets

```bash
lizard secrets delete OLD_KEY ANOTHER_KEY
```

### Import a dotenv file

```bash
cat .env | lizard secrets import
```

## See also

- [Variables & secrets](https://lizard.build/docs/variables) — scoping, precedence, and build-time vs. runtime behavior
- [Cross-service references](https://lizard.build/docs/variables/references) — read one service's values from another
- [Troubleshooting: a secret or reference isn't showing up](https://lizard.build/docs/variables/troubleshooting/reference-not-applied)
- [lizard run](https://lizard.build/docs/cli/run) — run a command locally with project + service secrets injected
