Usage
Secret renders sensitive material (API keys, webhook signing secrets, integration tokens) with masking, controlled reveal, and a copy action. It belongs in admin surfaces where operators verify or rotate credentials. The mental model is "this value is dangerous by default; the operator must opt in to see it, and the action is audited". Aligns with security UX basics: minimize exposure, log access server-side, and never let secrets leak into client analytics or support screenshots.
Input password pattern.| Variant | Purpose | Emphasis |
|---|---|---|
| Full mask | Hide every character until explicit reveal | Default for highest-risk secrets |
| Fingerprint (last-four) | Allow verification without full exposure | Use for "is this the right key?" workflows |
| Reveal-then-copy | Expose briefly for verification | Collapse on navigation; never persist revealed state |
formatMessage.Do
Don't
Screen reader users should understand when content is masked vs. revealed without broadcasting the value itself via a loud live region. Copy buttons need specific names ("Copy API key") instead of generic "Copy". See Accessibility for the full contract.