Conversation
Wraps /v0/variables so the SDK can manage the values behind the secret() placeholder helper, matching tb secret ls/set/rm. set() creates the secret if it doesn't exist yet, otherwise updates its value. Secret values are never returned by list() or surfaced in error messages. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
secret()helper only emits a{{ tb_secret(...) }}placeholder reference in datafiles — it can't manage the underlying secret value, so even an all-Python-SDK project neededtb secret seton the side.client.secretsnamespace (list()/set(name, value)/remove(name)) wrapping Tinybird's/v0/variablesendpoint, matchingtb secret ls/set/rm.set()checks whether the secret exists first (GET /v0/variables/{name}) and creates (POST /v0/variables) or updates (PUT /v0/variables/{name}) accordingly — mirroring the create-or-update logic in the Forward CLI's ownsecret setcommand./v0/variables, form-encodedname/valuebody,variableslist key) against the vendoredtinybirdCLI package'sTinyBclient (tinybird/tb/client.py) rather than guessing.Secret-value sensitivity:
list()only ever returnsname/created_at/updated_at(the API itself never returns values), and the error-raising path only ever surfaces the server's error body — the value passed toset()is never interpolated into an exception message. Covered by a dedicated regression test (test_set_secret_value_never_leaks_into_error_message).Closes https://linear.app/tinybird/issue/PROTM-2265/python-sdk-add-secrets-management-api-lssetrm
Checklist
lint,typecheck,test) —secrets/gitleaks fails in this sandbox only on an unrelated SSL cert error fetching its pre-commit envpre-commit run --all-filespasses locally (blocked by the same sandbox SSL/network limitation, not by this change)README.md) with a "Secrets Management" sectionCHANGELOG.mdwas updated when user-facing behavior changed