Your secrets are encrypted server-side. Your frontend never sees the real keys.
Name it after the service — STRIPE_KEY, OPENAI_KEY. Your app references the name, never the value.
Replace your direct API calls with fetch("/api/your-route"). The Hutch injects the secret and forwards it.
Point Stripe or GitHub at your Hutch URL. The Hutch verifies the signature — your app just reads the clean payload.
Webhook guide →The Hutch secures your secrets. The Farm gives Napoleon the tools to actually use them — running agents, executing pipelines, managing containers, and shipping work while you sleep.
Push a branch, Napoleon runs tests, opens a PR, and deploys — while you're away from your machine.
Run any container in The Pen — isolated, audited, accessible from anywhere, with secrets from your Hutch.
Every action logged. Every secret access recorded. Napoleon never acts without a receipt.
Health checks, cron jobs, multi-step pipelines. The Farm runs while you're living your life.
/api/* endpoints and won't be affected.
To disable this page, set HUTCH_LANDING=false in your container environment.