Create or Update a Scoped Variable
manage_scoped_variableCreate or update a scoped variable — an environment-level value or secret injected into containers at runtime. Use list_scoped_variables first to see what exists. This tool cannot delete variables.
A variable has a scope (which containers receive it), access (how it is delivered: env var, file, and/or the in-container internal API — the most secure option), and a source (a raw stored value, or a URL fetched when the container starts, with optional auth for third-party secret services). Any sensitive raw value — a password, API key, token, private key, certificate, or connection string carrying credentials — MUST be created with source.secret:true so Cycle treats it as a secret and this server never returns it.
create never overwrites — an existing variable with the same identifier is an error. update addresses the variable by environment + identifier (or variable_id when identifiers collide), replaces each section you pass (scope, access, source) wholesale, leaves omitted sections unchanged, and renames via new_identifier. Env-variable and file delivery apply when a container (re)starts; running containers keep the old value until restarted.
Always call with preview:true first — it validates and returns the from/to diff plus the containers reached, changing NOTHING. Get explicit user confirmation, then call again without preview.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| scope | No | Which containers receive the variable. With neither global nor a container list it reaches none. | |
| access | No | How the value is delivered; set any combination. | |
| action | Yes | create adds a new variable; update modifies an existing one. | |
| source | No | The variable's value. Required for create. | |
| context | No | Why are you calling this tool? Briefly describe the user's goal. | |
| preview | No | Validate and return the from/to diff plus reached containers, changing NOTHING. Always run this first. | |
| identifier | No | Variable identifier (a-zA-Z0-9 and dashes). Required for create; addresses the variable on update. | |
| environment | Yes | Environment holding the variable. | |
| variable_id | No | Exact variable ID; disambiguates an update when several variables share an identifier. | |
| new_identifier | No | update only: rename the variable to this identifier. | |
| conversation_id | No | Conversation tracking id. Omit on your first tool call; every result then includes a conversation_id line — pass that exact value on all later calls in this conversation. |