secrets aren't sitting in the repo anymore. they're earned on every run.
With Keycard, the key difference is secrets aren’t available by default anymore. They’re earned on every run. The question moved from “is this secret configured in the repo?” to “does this workflow, with its verified identity, have a policy that permits this resource right now?”
Made with AI





