Secrets and environment variables
Get your .env files and API keys to agents on other machines, without committing them.
An agent on another machine often needs your .env file or an API key. Sesh puts them there for you. Secrets only go one way: a machine never sends a file’s contents or a variable’s value back to any device.
Copy a project’s secret files
- Right-click a session and choose Secrets…, or press ⌘K and choose Project Secrets….
- Click Add File… and pick files on this Mac. Hidden files are shown.
If this Mac has its own copy of the same repository, a From This Mac section lists its secret files. Click Copy, or Copy All, to move them across in one go.
Each file goes into the project and every session folder of it on that machine. Sesh keeps it out of git, so no agent can commit it.
For each file:
- New sessions copies it into new sessions’ folders. On by default.
- Replace… swaps in a new version.
- Remove deletes it from the project and its sessions.
Set variables for a project
In the same Secrets sheet, under Variables, click Add Variable…. Type the name and the value. The project’s agents, terminals and setup commands get it.
Set variables for a whole machine
- Open Settings › Machines and click Details… next to the machine.
- Under Variables, click Add Variable….
Every project on that machine gets it. A project’s own value wins over the machine’s.
Tip.
ANTHROPIC_API_KEYset on a machine counts as signed in for Claude Code there.
Once saved, a variable shows as its name and dots. Click Set… to change it or remove it. New values reach agents started afterwards.
Is it encrypted?
Yes. Connections to your machines are encrypted, and Sesh checks each machine is the one you paired.
A machine paired with a much older version of Sesh may show Not encrypted. Sesh asks before sending anything to it; click Send Anyway only if you trust the network. Adding the machine again fixes it.
Good to know
- Files can be up to 1 MB each.
- Sesh won’t overwrite a file git already tracks.