How Acrosite handles secrets
GitHub tokens, deployment hook URLs, webhook secrets, and provider credentials stay server-side. You see safe status and masked metadata — never raw secrets, in the UI or in logs.
Connecting Acrosite to GitHub and a deployment trigger involves credentials. Acrosite is designed so those secrets stay server-side — you see safe status and masked metadata, never the raw secrets. This page explains what is protected.
Who this is for
Workspace Owners and Developers who connect integrations and want to know how the credentials are handled.
Secrets stay server-side
Sensitive values are used on the server and are not exposed to your browser:
- GitHub App keys and installation tokens.
- Deployment hook URLs.
- Webhook secrets and provider credentials.
What you see instead
In the dashboard, you see safe, useful information rather than raw secrets — for example:
- Connection status (such as Connected) and verification results.
- Masked deployment hook metadata, not the full URL.
- Test-trigger results and safe error summaries.
The deployment hook URL is masked in the interface so it cannot be read or copied.
Logs are sanitized
Publish Logs and Deployment Logs are designed to explain what happened without leaking secrets. They do not show tokens, full hook URLs, raw provider payloads, stack traces, cookies, session data, or environment variables. See Understand Publish Logs.