EAS Project Secrets and Least-Privilege Access Control
0 reputation · 30 Jul 2025, 02:26 UTC
Expo Application Services (EAS) allows the configuration of secrets at both the account and project levels to manage sensitive environment variables during the build process. Currently, these secrets are accessible to any user assigned the 'Admin' or 'Developer' role within a project.
In a large-scale organization, there is a requirement to implement a more granular permission boundary. Specifically, certain environment variables must be restricted from 'Developer' roles while remaining available to the EAS Build service account to ensure a least-privilege security model.
Given the current role-based access control (RBAC) in the Expo dashboard, what are the available methods to isolate specific project secrets from human developers without removing their ability to trigger builds? Is there a mechanism to scope secrets exclusively to the build pipeline?