Manage Secrets in GCP Secret Manager
GCP Secret Manager is a fully managed service for storing, managing, and accessing sensitive information such as API keys, passwords, and certificates. It allows you to store secrets centrally with encryption, automate versioning, and control access using Google Cloud’s IAM policies.
This guide will show you how to use GCP Secret Manager to manage user credentials for authentication plugin key-auth and how to retrieve the secret in APISIX.
Prerequisite(s)
- Install Docker.
- Install cURL to send requests to the services for validation.
- Follow the Getting Started tutorial to start a new APISIX instance in Docker.
- Have a GCP account and enable Secret Manager.
Create a Secret in GCP Secret Manager
In this section, you will be creating a secret to store the key-auth authentication key for consumer john.
Navigate to GCP Secret Manager in the console and create a secret. Fill in the name apisix-john-key-auth and the secret john-key:

Review the rest of the information and finish secret creation. You should see the secret listed in GCP Secret Manager:
