Secrets
Write-only credentials: the keys your integrations need, kept so nobody can read them back.
A secret is a credential (an API key, a token) that an integration needs to reach an outside service. Secrets are your part of an integration: your agent builds the wiring and references a secret by name; you set its value.
#Write-only, on purpose
Once you save a secret's value, it can't be read back: not by you in the UI, not by your agent, not through the connection. You see its name and a masked hint, never the value. To rotate a credential, paste a new value over the old one.
This means a connected agent can build a fully working integration without ever being able to exfiltrate your keys, and a leaked screenshot of your Secrets page reveals nothing usable.
#Setting one
You set secret values in Dashboard → Secrets, an owner/admin action. Maintainers can see that a secret exists (its name and description, so they know an integration is wired) but nobody reads a value back at any role, including yours.
See Integrations and secrets for the full walkthrough and Team for who can do what.