Secrets and credentials
Agent encrypts keys and tokens in a vault. It shows only a short hint, never the full value, and never sends a secret out.
The vaultLink to The vault
Model account keys, integration tokens, trigger tokens and WhatsApp tokens are encrypted in the vault (AES-256-GCM). A resource of the kind Credential is only a reference to the vault.
What you see againLink to What you see again
- An API key: its last four characters.
- An AWS key: the first and last four characters.
- A Google service account: its email.
- A runner token or API token: only at creation, one time.
Secrets never leaveLink to Secrets never leave
The outgoing check blocks secrets in any outgoing call. Agent refuses the whole runner result when it contains a token-shaped string.
DisconnectLink to Disconnect
Disconnecting a model account deletes its credential. Past spend stays recorded.
Checked against the product on 2026-10-05.
Was this helpful?
Related articles
- Model accounts and API keysConnect your own API keys or cloud model accounts. Work you ask for uses your accounts first, then the organization's, then the platform's.
- API tokensAPI tokens are machine credentials for CI, scripts and MCP clients. Each token has one role and expires.
- Security overviewAgent limits what workers can do with roles, policies, approvals, budgets and the kill switch, checks every outgoing call for secrets, and records everything in a tamper-evident log.