Secrets

Organization Settings > Secrets is the write-only vault for provider and ERP credentials agents use to reach external services. Keys go in; they never come back out through the API.

Rotation and the change trail, not just the vault

Connected Apps is where you decide what a tool is allowed to do; Secrets is where the credentials behind that decision live and get rotated. Save a new value here and the old one is invalidated immediately, so rotating a compromised or expiring key does not require touching the app configuration at all. Every add, update, and rotation is a recorded event: the connections list shows status and metadata afterward, never the value, but who changed a secret and when is never a mystery.

The Secrets admin page with the provider credential vault
Keys go in. They never come back out through the API, even to an admin.