Skip to main content
Credentials are API keys and tokens your agents use to sign into third-party services on your behalf. They are stored encrypted, and once saved, the value can be replaced but never read back. You manage credentials from Settings > Credentials.

Add a credential

1

Open Credentials settings

Go to Settings > Credentials in the sidebar.
2

Click Add credential

The Add credential button opens a dialog where you name the credential and paste its value.
3

Name and save

Enter a name such as NOTION_TOKEN. Names must start with a letter and contain only letters, digits, and underscores. Paste the value and click Add. The value is stored encrypted and is never shown again.
Managed credentials (for example, those created by an integration such as Telegram) cannot be edited from this page. They show a Managed by label and a link to the integration that owns them.

Grant credentials to agents

Nothing is granted by default, and All agents never includes Maya. You must explicitly choose which agents may use each credential.

Enable for all agents (except Maya)

On the Credentials page, flip the All agents switch next to a credential. This grants it to every custom agent you own. Maya is excluded and must be granted separately if you want her to use it.

Grant to specific agents

  1. Click the access pill next to a credential (it shows the current agent count).
  2. In the Manage Credential Access dialog, check the agents you want to grant.
  3. Click Save.
Agents that inherit access from the All agents switch show a via All agents label. If you uncheck one of those agents, it writes an explicit override rather than removing a direct grant.

Rotate a credential

If a key expires or is compromised, you can replace it:
  1. Click the rotate icon next to the credential.
  2. Paste the new value in the Replace credential dialog.
  3. Click Replace. The new value is saved, and all granted agents receive it on their next turn.
The current value cannot be shown. Rotating is the only way to change a stored credential.

Delete a credential

  1. Click the delete icon next to the credential.
  2. Confirm in the dialog. The credential is removed permanently, and every agent that had access loses it immediately.
Deletion is irreversible. You cannot recover the value, and any agent using it will stop working with that service until you add a new credential.

Credential requests in chat

Sometimes an agent needs a credential it does not have. It raises a Credential Request in chat, asking you for the specific keys it needs. When you see a credential request card:
  1. Review the names of the credentials being asked for.
  2. Choose whether to enter new values or reuse existing ones you already stored.
  3. Click Save. The values are stored, granted to the requesting agent, and the agent resumes automatically.
The agent only learns which credential names were fulfilled. The actual values never pass through chat.

Security notes

  • Values are encrypted before they touch the database.
  • No endpoint returns a credential value, not even to its owner.
  • Last-four characters are shown only to help you recognize which key is stored.
  • Managed credentials are handled by their owning integration and should be changed from the integration’s settings page.

Next steps

Connect Apps

Connect apps that use these credentials.

Skills

Install skills that may need credentials.

Browsers

Pair a browser for web-based access.