---
title: "Node"
icon: "node"
---
If you're working with Node.js, the official [infisical-node](https://github.com/Infisical/infisical-node) package is the easiest way to fetch and work with secrets for your application.
## Basic Usage
```js
import express from "express";
import InfisicalClient from "infisical-node";
const app = express();
const PORT = 3000;
const client = new InfisicalClient({
token: "YOUR_INFISICAL_TOKEN"
});
app.get("/", async (req, res) => {
// access value
const name = await client.getSecret("NAME");
res.send(`Hello! My name is: ${name.secretValue}`);
});
app.listen(PORT, async () => {
// initialize client
console.log(`App listening on port ${port}`);
});
```
This example demonstrates how to use the Infisical SDK with an Express application. The application retrieves a secret named "NAME" and responds to requests with a greeting that includes the secret value.
We do not recommend hardcoding your [Infisical
Token](/getting-started/dashboard/token). Setting it as an environment
variable would be best.
## Installation
Run `npm` to add `infisical-node` to your project.
```console
$ npm install infisical-node --save
```
## Configuration
Import the SDK and create a client instance with your Infisical token.
```js
import InfisicalClient from "infisical-node";
const client = new InfisicalClient({
token: "your_infisical_token"
});
// your app logic
```
```js
const InfisicalClient = require("infisical-node");
const client = new InfisicalClient({
token: "your_infisical_token"
});
// your app logic
````
### Parameters
An [Infisical Token](/getting-started/dashboard/token) scoped to a project
and environment
Your self-hosted absolute site URL including the protocol (e.g.
`https://app.infisical.com`)
Time-to-live (in seconds) for refreshing cached secrets. Default: `300`.
Whether or not debug mode is on
## Caching
The SDK caches every secret and updates it periodically based on the provided `cacheTTL`. For example, if `cacheTTL` of `300` is provided, then a secret will be refetched 5 minutes after the first fetch; if the fetch fails, the cached secret is returned.
For optimal performance, we recommend creating a single instance of the Infisical client and exporting it to be used across your entire app to take advantage of caching benefits.
## Working with Secrets
### client.getAllSecrets()
```js
const secrets = await client.getAllSecrets();
```
Retrieve all secrets within the Infisical project and environment that client is connected to
### client.getSecret(secretName, options)
```js
const secret = await client.getSecret("API_KEY");
const value = secret.secretValue; // get its value
```
Retrieve a secret from Infisical.
By default, `getSecret()` fetches and returns a personal secret. If not found, it returns a shared secret, or tries to retrieve the value from `process.env`. If a secret is fetched, `getSecret()` caches it to reduce excessive calls and re-fetches periodically based on the `cacheTTL` option (default is `300` seconds) when initializing the client — for more information, see the caching section.
### Parameters
The key of the secret to retrieve
The type of the secret. Valid options are "shared" or "personal"
### client.createSecret(secretName, secretValue, options)
```js
const newApiKey = await client.createSecret("API_KEY", "FOO");
```
Create a new secret in Infisical.
The key of the secret to create
The value of the secret to create
The type of the secret. Valid options are "shared" or "personal". A personal secret can only be created if a shared secret with the same name exists.
### client.updateSecret(secretName, secretValue, options)
```js
const updatedApiKey = await client.updateSecret("API_KEY", "BAR");
```
Update an existing secret in Infisical.
### Parameters
The key of the secret to update
The new value of the secret
The type of the secret. Valid options are "shared" or "personal"
### client.deleteSecret(secretName, options)
```js
const deletedSecret = await client.deleteSecret("API_KEY");
```
Delete a secret in Infisical.
The key of the secret to delete
The type of the secret. Valid options are "shared" or "personal". Note that deleting a shared secret also deletes all associated personal secrets.