Skip to content
← Help center

Compute

Store third-party skill credentials in Vault

Production guidance · Console v0.1 / v0.2 · Updated

What belongs in Vault

Vault holds named third-party credentials used by a skill's own runtime code. These are different from inference routing credentials. The skill determines the environment variable name it expects; consult its instructions before choosing a name.

Save or rotate a secret

Open your workspace's Vault, choose Set secret, and enter the name and value. Saving an existing name replaces its value. Secret values are write-only: listings show the name, presence, and timestamps, never the saved value.

A skill reports a missing credential

  • Check that the secret was saved in the intended workspace.
  • Compare the secret name exactly with the variable the skill reads, including capitalisation.
  • Confirm at the provider that the credential is valid and has the required access.
  • Share the missing variable's name with support, never the secret value.

A skill should report an absent required key clearly. Do not ask it to print environment variables or credentials to diagnose the problem.

A secret was lost

Rotate the credential at its provider, then save the replacement under the same Vault name. The old plaintext cannot be read back from Vault. See Vault reference for API operations and sandbox consumption.

Sources and scope

This guide is based on the published developer documentation linked below. Check model and workspace availability in your environment.