Official agent skill

Azure Keyvault Secrets TS

by microsoft in microsoft/skills

Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets).

OfficialMITAuto-check passed

Install Azure Keyvault Secrets TS

skills CLI
$ npx skills add microsoft/skills --skill azure-keyvault-secrets-ts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-keyvault-secrets-ts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-typescript/skills/azure-keyvault-secrets-ts .claude/skills/azure-keyvault-secrets-ts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-keyvault-secrets-ts
GitHub stars
3.1k
Used in
5 other repos
Token cost
~1.7k tokens
SKILL.md length
112 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets).

  • Works in 6 steps: Use DefaultAzureCredential for local… → Enable soft-delete - Required for… → Set expiration dates - On both keys and… → …
  • Storing and retrieving application secrets
  • SKILL.md covers Installation, Environment Variables, Authentication and Secrets Operations, plus 6 more sections
  • Calls npm; reaches learn.microsoft.com; needs AZURE_TOKEN_CREDENTIALS

What it does

Azure Keyvault Secrets TS is an agent skill from microsoft/skills, published by the product's own GitHub organization. Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets). Use when storing and retrieving application secrets or configuration values.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/keys.md` and `references/secrets.md`).

It works with Azure Key Vault, TypeScript and JavaScript. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Storing and retrieving application secrets
  • Configuration values

Example prompts

  • “/azure-keyvault-secrets-ts”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Use DefaultAzureCredential for local development; use ManagedIdentityCredential or WorkloadIdentityCredential for production
  2. Enable soft-delete - Required for production vaults
  3. Set expiration dates - On both keys and secrets
  4. Use key rotation policies - Automate key rotation
  5. Limit key operations - Only grant needed operations (encrypt, sign, etc.)
  6. Browser not supported - These SDKs are Node.js only

What it can do on your machine

Read from SKILL.md and the folder at commit 3898ec8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Keyvault Secrets TS loads about 1.7k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 48 tokens; SKILL.md has 112 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 3898ec8, republished under its MIT licence (© microsoft). 112 words, ~1,700 tokens.

Download SKILL.mdSave it as .claude/skills/azure-keyvault-secrets-ts/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-keyvault-secrets-ts
description
Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets). Use when storing and retrieving application secrets or configuration values.
license
MIT
metadata.author
Microsoft
metadata.version
1.0.0
metadata.package
@azure/keyvault-secrets

Azure Key Vault Secrets SDK for TypeScript

Manage secrets with Azure Key Vault.

Installation

bash
# Secrets SDK
npm install @azure/keyvault-secrets @azure/identity

Environment Variables

bash
KEY_VAULT_URL=https://<vault-name>.vault.azure.net
# Or
AZURE_KEYVAULT_NAME=<vault-name>
AZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production

Authentication

typescript
import { DefaultAzureCredential, ManagedIdentityCredential } from "@azure/identity";
import { SecretClient } from "@azure/keyvault-secrets";

// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=<specific_credential>
const credential = new DefaultAzureCredential({requiredEnvVars: ["AZURE_TOKEN_CREDENTIALS"]});
// Or use a specific credential directly in production:
// See https://learn.microsoft.com/javascript/api/overview/azure/identity-readme?view=azure-node-latest#credential-classes
// const credential = new ManagedIdentityCredential();
const vaultUrl = `https://${process.env.AZURE_KEYVAULT_NAME}.vault.azure.net`;

const keyClient = new KeyClient(vaultUrl, credential);
const secretClient = new SecretClient(vaultUrl, credential);

Secrets Operations

Create/Set Secret
typescript
const secret = await secretClient.setSecret("MySecret", "secret-value");

// With attributes
const secretWithAttrs = await secretClient.setSecret("MySecret", "value", {
  enabled: true,
  expiresOn: new Date("2025-12-31"),
  contentType: "application/json",
  tags: { environment: "production" }
});
Get Secret
typescript
// Get latest version
const secret = await secretClient.getSecret("MySecret");
console.log(secret.value);

// Get specific version
const specificSecret = await secretClient.getSecret("MySecret", {
  version: secret.properties.version
});
List Secrets
typescript
for await (const secretProperties of secretClient.listPropertiesOfSecrets()) {
  console.log(secretProperties.name);
}

// List versions
for await (const version of secretClient.listPropertiesOfSecretVersions("MySecret")) {
  console.log(version.version);
}
Delete Secret
typescript
// Soft delete
const deletePoller = await secretClient.beginDeleteSecret("MySecret");
await deletePoller.pollUntilDone();

// Purge (permanent)
await secretClient.purgeDeletedSecret("MySecret");

// Recover
const recoverPoller = await secretClient.beginRecoverDeletedSecret("MySecret");
await recoverPoller.pollUntilDone();

Keys Operations

Create Keys
typescript
// Generic key
const key = await keyClient.createKey("MyKey", "RSA");

// RSA key with size
const rsaKey = await keyClient.createRsaKey("MyRsaKey", { keySize: 2048 });

// Elliptic Curve key
const ecKey = await keyClient.createEcKey("MyEcKey", { curve: "P-256" });

// With attributes
const keyWithAttrs = await keyClient.createKey("MyKey", "RSA", {
  enabled: true,
  expiresOn: new Date("2025-12-31"),
  tags: { purpose: "encryption" },
  keyOps: ["encrypt", "decrypt", "sign", "verify"]
});
Get Key
typescript
const key = await keyClient.getKey("MyKey");
console.log(key.name, key.keyType);
List Keys
typescript
for await (const keyProperties of keyClient.listPropertiesOfKeys()) {
  console.log(keyProperties.name);
}
Rotate Key
typescript
// Manual rotation
const rotatedKey = await keyClient.rotateKey("MyKey");

// Set rotation policy
await keyClient.updateKeyRotationPolicy("MyKey", {
  lifetimeActions: [{ action: "Rotate", timeBeforeExpiry: "P30D" }],
  expiresIn: "P90D"
});
Delete Key
typescript
const deletePoller = await keyClient.beginDeleteKey("MyKey");
await deletePoller.pollUntilDone();

// Purge
await keyClient.purgeDeletedKey("MyKey");

Cryptographic Operations

Create CryptographyClient
typescript
import { CryptographyClient } from "@azure/keyvault-keys";

// From key object
const cryptoClient = new CryptographyClient(key, credential);

// From key ID
const cryptoClient = new CryptographyClient(key.id!, credential);
Encrypt/Decrypt
typescript
// Encrypt
const encryptResult = await cryptoClient.encrypt({
  algorithm: "RSA-OAEP",
  plaintext: Buffer.from("My secret message")
});

// Decrypt
const decryptResult = await cryptoClient.decrypt({
  algorithm: "RSA-OAEP",
  ciphertext: encryptResult.result
});

console.log(decryptResult.result.toString());
Sign/Verify
typescript
import { createHash } from "node:crypto";

// Create digest
const hash = createHash("sha256").update("My message").digest();

// Sign
const signResult = await cryptoClient.sign("RS256", hash);

// Verify
const verifyResult = await cryptoClient.verify("RS256", hash, signResult.result);
console.log("Valid:", verifyResult.result);
Wrap/Unwrap Keys
typescript
// Wrap a key (encrypt it for storage)
const wrapResult = await cryptoClient.wrapKey("RSA-OAEP", Buffer.from("key-material"));

// Unwrap
const unwrapResult = await cryptoClient.unwrapKey("RSA-OAEP", wrapResult.result);

Backup and Restore

typescript
// Backup
const keyBackup = await keyClient.backupKey("MyKey");
const secretBackup = await secretClient.backupSecret("MySecret");

// Restore (can restore to different vault)
const restoredKey = await keyClient.restoreKeyBackup(keyBackup!);
const restoredSecret = await secretClient.restoreSecretBackup(secretBackup!);

Key Types

typescript
import {
  KeyClient,
  KeyVaultKey,
  KeyProperties,
  DeletedKey,
  CryptographyClient,
  KnownEncryptionAlgorithms,
  KnownSignatureAlgorithms
} from "@azure/keyvault-keys";

import {
  SecretClient,
  KeyVaultSecret,
  SecretProperties,
  DeletedSecret
} from "@azure/keyvault-secrets";

Error Handling

typescript
try {
  const secret = await secretClient.getSecret("NonExistent");
} catch (error: any) {
  if (error.code === "SecretNotFound") {
    console.log("Secret does not exist");
  } else {
    throw error;
  }
}

Best Practices

  1. Use DefaultAzureCredential for local development; use ManagedIdentityCredential or WorkloadIdentityCredential for production
  2. Enable soft-delete - Required for production vaults
  3. Set expiration dates - On both keys and secrets
  4. Use key rotation policies - Automate key rotation
  5. Limit key operations - Only grant needed operations (encrypt, sign, etc.)
  6. Browser not supported - These SDKs are Node.js only

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/plugins/azure-sdk-typescript/skills/azure-keyvault-secrets-ts of microsoft/skills.

  • SKILL.md
  • references/keys.md
  • references/secrets.md

Open the folder on GitHubat commit 3898ec8

Used in 5 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in microsoft/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Keyvault Secrets TS next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Keyvault Secrets TS compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Keyvault Secrets TS this skillmicrosoft/skills3.1k5 repos~1.7kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Install Anti Sloptrycompai/crm11k1 repos~881Automated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k—~2.2kAutomated safety check: PassMIT
Bun DevelopmentGabrielMartinMoran/mind14812 repos~3.5kAutomated safety check: NotesMIT
Generate Release Notesteambit/bit18k—~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub stars~2.2k tokensUpdated 28 days ago
    DevelopmentAuto-check passed
  • Bun Development

    GabrielMartinMoran/mind

    Modern JavaScript/TypeScript development with Bun runtime. An agent skill from GabrielMartinMoran/mind.

    148 GitHub starsUsed in 12 repos~3.5k tokens
    Auto-check: notes
  • Generate comprehensive release notes for Bit from git commits and pull requests.

    18k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Hot Monitor

    liyupi/yupi-hot-monitor

    AI hotspot monitoring and trending topic discovery across multiple sources (Bing, Google, DuckDuckGo, HackerNews, Sogou, Bilibili, Weibo, Twitter).

    718 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 5 repos~496 tokens
    Auto-check passed
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Skill Creator

    microsoft/skills

    Official

    Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services.

    3.1k GitHub starsUsed in 5 repos~17k tokens
    Auto-check passed

Questions about Azure Keyvault Secrets TS

What does Azure Keyvault Secrets TS do?

Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets). Azure Keyvault Secrets TS is an agent skill from microsoft/skills, published by the product's own GitHub organization. Manage secrets using Azure Key Vault Secrets SDK for JavaScript (@azure/keyvault-secrets).

When should I use Azure Keyvault Secrets TS?

Azure Keyvault Secrets TS fits situations like: storing and retrieving application secrets; configuration values.

How do I install Azure Keyvault Secrets TS in Claude Code?

Run `npx skills add microsoft/skills --skill azure-keyvault-secrets-ts -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-typescript/skills/azure-keyvault-secrets-ts in microsoft/skills) into .claude/skills/azure-keyvault-secrets-ts in your project. Claude Code loads it when a task matches its description.

How do I install Azure Keyvault Secrets TS in Codex?

Run `npx skills add microsoft/skills --skill azure-keyvault-secrets-ts -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-typescript/skills/azure-keyvault-secrets-ts in microsoft/skills) into .agents/skills/azure-keyvault-secrets-ts in your project. Codex loads it when a task matches its description.

Can I use Azure Keyvault Secrets TS in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-keyvault-secrets-ts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-keyvault-secrets-ts, .gemini/skills/azure-keyvault-secrets-ts, .github/skills/azure-keyvault-secrets-ts and .opencode/skills/azure-keyvault-secrets-ts in your project.

What does Azure Keyvault Secrets TS need to run?

Going by SKILL.md and its folder, Azure Keyvault Secrets TS needs the command-line tools its instructions call (npm) and credentials named AZURE_TOKEN_CREDENTIALS. Our summary lists: Node.js.

Does Azure Keyvault Secrets TS access the network?

SKILL.md names 1 domain. In commands or code: learn.microsoft.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Keyvault Secrets TS safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Keyvault Secrets TS use?

Azure Keyvault Secrets TS is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Keyvault Secrets TS use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.4k tokens, read only when the agent opens those files.

What are the alternatives to Azure Keyvault Secrets TS?

Skills that share tags, products or a category with Azure Keyvault Secrets TS: Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Install Anti Slop (trycompai/crm, 11k stars), Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars) and Bun Development (GabrielMartinMoran/mind, 148 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Keyvault Secrets TS?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,094 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.