> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kolmena.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add and Manage Credentials for Your Agents

> Store encrypted credentials, grant them to specific agents, and respond to credential requests from chat. Values are never shown again after saving.

Credentials are API keys and tokens your agents use to sign into third-party services on your behalf. They are stored encrypted, and once saved, the value can be replaced but never read back. You manage credentials from **Settings > Credentials**.

## Add a credential

<Steps>
  <Step title="Open Credentials settings">
    Go to **Settings > Credentials** in the sidebar.
  </Step>

  <Step title="Click Add credential">
    The **Add credential** button opens a dialog where you name the credential and paste its value.
  </Step>

  <Step title="Name and save">
    Enter a name such as `NOTION_TOKEN`. Names must start with a letter and contain only letters, digits, and underscores. Paste the value and click **Add**. The value is stored encrypted and is never shown again.
  </Step>
</Steps>

<Note>
  Managed credentials (for example, those created by an integration such as Telegram) cannot be edited from this page. They show a **Managed by** label and a link to the integration that owns them.
</Note>

## Grant credentials to agents

Nothing is granted by default, and **All agents** never includes Maya. You must explicitly choose which agents may use each credential.

### Enable for all agents (except Maya)

On the Credentials page, flip the **All agents** switch next to a credential. This grants it to every custom agent you own. Maya is excluded and must be granted separately if you want her to use it.

### Grant to specific agents

1. Click the access pill next to a credential (it shows the current agent count).
2. In the **Manage Credential Access** dialog, check the agents you want to grant.
3. Click **Save**.

Agents that inherit access from the **All agents** switch show a *via All agents* label. If you uncheck one of those agents, it writes an explicit override rather than removing a direct grant.

## Rotate a credential

If a key expires or is compromised, you can replace it:

1. Click the rotate icon next to the credential.
2. Paste the new value in the **Replace credential** dialog.
3. Click **Replace**. The new value is saved, and all granted agents receive it on their next turn.

<Warning>
  The current value cannot be shown. Rotating is the only way to change a stored credential.
</Warning>

## Delete a credential

1. Click the delete icon next to the credential.
2. Confirm in the dialog. The credential is removed permanently, and every agent that had access loses it immediately.

<Warning>
  Deletion is irreversible. You cannot recover the value, and any agent using it will stop working with that service until you add a new credential.
</Warning>

## Credential requests in chat

Sometimes an agent needs a credential it does not have. It raises a **Credential Request** in chat, asking you for the specific keys it needs.

When you see a credential request card:

1. Review the names of the credentials being asked for.
2. Choose whether to enter new values or reuse existing ones you already stored.
3. Click **Save**. The values are stored, granted to the requesting agent, and the agent resumes automatically.

The agent only learns which credential names were fulfilled. The actual values never pass through chat.

## Security notes

* Values are encrypted before they touch the database.
* No endpoint returns a credential value, not even to its owner.
* Last-four characters are shown only to help you recognize which key is stored.
* Managed credentials are handled by their owning integration and should be changed from the integration's settings page.

## Next steps

<CardGroup cols={3}>
  <Card title="Connect Apps" color="#FE4F32" icon="plug" href="/integrations/connect-apps">
    Connect apps that use these credentials.
  </Card>

  <Card title="Skills" color="#FE4F32" icon="wand-magic-sparkles" href="/integrations/skills">
    Install skills that may need credentials.
  </Card>

  <Card title="Browsers" color="#FE4F32" icon="globe" href="/integrations/browsers">
    Pair a browser for web-based access.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.