docs/documentation/platform/secrets-mgmt/quick-starts/deliver-first-secret.mdx
This quickstart guide walks you through the recommended secrets management workflow for local development. You'll create a project, add secrets to one of its environments, and inject them into your local application using the Infisical CLI, all without needing a .env file.
In Infisical, a project holds all secrets for one application or service. To create a project:
<Steps> <Step> Log in to [Infisical](https://app.infisical.com). </Step> <Step> Select **Secrets Management** > **+ Add New Project**. </Step> <Step> In the **Project Name** field, enter a name for the project (e.g., `orders-service`). </Step> <Step> Select **Create Project**. </Step> </Steps>This opens your new project in the Development environment:
<Frame>  </Frame> <Note> Within a project, secrets are organized across [environments](/documentation/platform/secrets-mgmt/project#project-environments). Every new project starts with three environments: **Development**, **Staging**, and **Production**. </Note>You have two options for adding secrets to your project:
<Tabs> <Tab title="Create secrets manually"> To create a new secret from scratch:<Steps>
<Step>
Select **+ Add a New Secret**.
</Step>
<Step>
In the **Key** and **Value** fields, enter a key-value pair. For example:
<Frame>

</Frame>
</Step>
<Step>
Select **Create Secret**.
</Step>
<Step>
Repeat these steps for each key-value pair you want to add.
</Step>
</Steps>
<Steps>
<Step>
Drag and drop the file containing your secrets (or enter the file's contents manually by selecting **Paste Secrets**).
</Step>
<Step>
Review the discovered secrets. For example:
<Frame>

</Frame>
</Step>
<Step>
Select **Upload Secrets**.
</Step>
</Steps>
Now that you've set up a project that holds your secrets in Infisical, you can connect your application and give it access to those secrets at runtime.
Authenticate with the Infisical CLI by running infisical login:
infisical login
This prompts you to select your hosting option, then opens your browser to complete the login.
<Note> In a containerized environment such as WSL 2 or Codespaces, run `infisical login -i` to avoid browser-based login. </Note>Next, connect your application to your Infisical project:
<Steps> <Step> In your application's directory, link it to the Infisical project you created by running [`infisical init`](/cli/commands/init):```bash
infisical init
```
```json .infisical.json
{
"workspaceId": "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"defaultEnvironment": "",
"gitBranchToEnvironmentMapping": null
}
```
<Note>
`.infisical.json` files contain no secrets and are safe to commit to version control systems like git.
</Note>
Now that your Infisical project is configured within your application, Infisical can provide the secrets.
Start your application by wrapping its start command with infisical run:
infisical run --env=dev -- flask run
infisical run --env=dev -- go run main.go
Infisical fetches the secrets and injects them as environment variables. This lets your application read the secrets from its environment at runtime.
<Check> You can now manage your application's secrets through Infisical without needing a `.env` file. </Check>