--- title: "Create secrets" --- In this example, we demonstrate how to add secrets to a project and environment using an Infisical Token. Prerequisites: - Set up and add envars to [Infisical Cloud](https://app.infisical.com) - Create an [Infisical Token](../../../getting-started/dashboard/token) for your project and environment. - Grasp a basic understanding of the system and its underlying cryptography [here](/api-reference/overview/introduction). ## Flow 1. [Get your Infisical Token data](/api-reference/endpoints/service-tokens/get) including a (encrypted) project key. 2. Decrypt the (encrypted) project key with the key from your Infisical Token. 3. Encrypt your secret(s) with the project key 4. [Send (encrypted) secret(s) to Infical](/api-reference/endpoints/secrets/create) ## Example ```js const crypto = require('crypto'); const axios = require('axios'); const nacl = require('tweetnacl'); const BASE_URL = 'https://app.infisical.com'; const ALGORITHM = 'aes-256-gcm'; const BLOCK_SIZE_BYTES = 16; const encrypt = ({ text, secret }) => { const iv = crypto.randomBytes(BLOCK_SIZE_BYTES); const cipher = crypto.createCipheriv(ALGORITHM, secret, iv); let ciphertext = cipher.update(text, 'utf8', 'base64'); ciphertext += cipher.final('base64'); return { ciphertext, iv: iv.toString('base64'), tag: cipher.getAuthTag().toString('base64') }; } const decrypt = ({ ciphertext, iv, tag, secret}) => { const decipher = crypto.createDecipheriv( ALGORITHM, secret, Buffer.from(iv, 'base64') ); decipher.setAuthTag(Buffer.from(tag, 'base64')); let cleartext = decipher.update(ciphertext, 'base64', 'utf8'); cleartext += decipher.final('utf8'); return cleartext; } const createSecrets = async () => { const serviceToken = ''; const serviceTokenSecret = serviceToken.substring(serviceToken.lastIndexOf('.') + 1); const secretType = 'shared'; // 'shared' or 'personal' const secretKey = 'some_key'; const secretValue = 'some_value'; const secretComment = 'some_comment'; // 1. Get your Infisical Token data const { data: serviceTokenData } = await axios.get( `${BASE_URL}/api/v2/service-token`, { headers: { Authorization: `Bearer ${serviceToken}` } } ); // 2. Decrypt the (encrypted) project key with the key from your Infisical Token const projectKey = decrypt({ ciphertext: serviceTokenData.encryptedKey, iv: serviceTokenData.iv, tag: serviceTokenData.tag, secret: serviceTokenSecret }); // 3. Encrypt your secret(s) with the project key const { ciphertext: secretKeyCiphertext, iv: secretKeyIV, tag: secretKeyTag } = encrypt({ text: secretKey, secret: projectKey }); const { ciphertext: secretValueCiphertext, iv: secretValueIV, tag: secretValueTag } = encrypt({ text: secretValue, secret: projectKey }); const { ciphertext: secretCommentCiphertext, iv: secretCommentIV, tag: secretCommentTag } = encrypt({ text: secretComment, secret: projectKey }); const secret = { type: secretType, secretKeyCiphertext, secretKeyIV, secretKeyTag, secretValueCiphertext, secretValueIV, secretValueTag, secretCommentCiphertext, secretCommentIV, secretCommentTag } // 4. Send (encrypted) secret(s) to Infisical await axios.post( `${BASE_URL}/api/v2/secrets`, { workspaceId: serviceTokenData.workspace, environment: serviceTokenData.environment, secrets: [secret] }, { headers: { Authorization: `Bearer ${serviceToken}` } } ); } createSecrets(); ``` This example uses [TweetNaCl.js](https://tweetnacl.js.org/#/), a port of TweetNacl/Nacl, to perform asymmeric decryption of the project key but there are ports of NaCl available in every major language.