Integrations and secrets

Connect your site to outside services, and store the credentials safely.

Sites often need to reach other services: take a payment, send an email, sync a CRM, pull an inventory feed. Your agent builds the connection; you supply the credential. That division is the whole point: the wiring lives with the agent, the secret key lives with you.

#How it works

  • Your agent builds an integration, a configured call to the outside service (its address, what to send, how to authenticate).
  • Where the service needs a credential (an API key, a token), the integration references a secret by name.
  • You set that secret's value in Dashboard → Secrets. The agent only ever refers to it by name; it never sees the value.

#Setting a secret

  1. Go to Dashboard → Secrets and create a secret (or your agent tells you which name to use).
  2. Paste the value: the API key from Stripe, the token from your email provider, etc.
  3. That's it. The integration referencing that name now authenticates correctly.

Some services need more than one value. An OAuth 1.0a integration, the kind X uses, names four secrets, one for each of its credentials. See Integrations.

Setting a secret's value is an admin action. Maintainers can see that a secret exists (its name and description, so they know an integration is wired), but nobody can read a value back at any role, including yours. See roles.

#Secrets are write-only

Once saved, a secret's value can't be read back: not by you in the UI, not by your agent, not through the connection. You'll see its name and a masked hint, never the value. To rotate a credential, paste a new value over the old one.

This is deliberate. It means a connected agent can build a fully working integration without ever being able to exfiltrate your keys, and a leaked screenshot of your Secrets page reveals nothing usable.

A workflow with a scope goes one step further and names the secrets it may use, so an agent can call a workflow that holds a key without ever getting to use that key itself. See Scope and secrets.

#A typical setup

Say you're adding Stripe checkout:

  1. Your agent builds the checkout page and the payment integration, and tells you it references a secret named (say) stripe-key.
  2. You create stripe-key in Secrets and paste your Stripe key.
  3. Your agent tests the integration against the live service to confirm the key is wired correctly.

From then on it just works, and your key stays yours.