Integrations and secrets
Connect your site to outside services, and store the credentials safely.
Sites often need to reach other services: take a payment, send an email, sync a CRM, pull an inventory feed. Your agent builds the connection; you supply the credential. That division is the whole point: the wiring lives with the agent, the secret key lives with you.
#How it works
- Your agent builds an integration, a configured call to the outside service (its address, what to send, how to authenticate).
- Where the service needs a credential (an API key, a token), the integration references a secret by name.
- You set that secret's value in Dashboard → Secrets. The agent only ever refers to it by name; it never sees the value.
#Setting a secret
- Go to Dashboard → Secrets and create a secret (or your agent tells you which name to use).
- Paste the value: the API key from Stripe, the token from your email provider, etc.
- That's it. The integration referencing that name now authenticates correctly.
Some services need more than one value. An OAuth 1.0a integration, the kind X uses, names four secrets, one for each of its credentials. See Integrations.
Setting a secret's value is an admin action. Maintainers can see that a secret exists (its name and description, so they know an integration is wired), but nobody can read a value back at any role, including yours. See roles.
#Secrets are write-only
Once saved, a secret's value can't be read back: not by you in the UI, not by your agent, not through the connection. You'll see its name and a masked hint, never the value. To rotate a credential, paste a new value over the old one.
This is deliberate. It means a connected agent can build a fully working integration without ever being able to exfiltrate your keys, and a leaked screenshot of your Secrets page reveals nothing usable.
A workflow with a scope goes one step further and names the secrets it may use, so an agent can call a workflow that holds a key without ever getting to use that key itself. See Scope and secrets.
#A typical setup
Say you're adding Stripe checkout:
- Your agent builds the checkout page and the payment integration, and tells you it references
a secret named (say)
stripe-key. - You create
stripe-keyin Secrets and paste your Stripe key. - Your agent tests the integration against the live service to confirm the key is wired correctly.
From then on it just works, and your key stays yours.