Secrets

Organization Settings > Secrets is the write-only vault for provider and ERP credentials agents use to reach external services. Keys go in; they never come back out through the API.

Write-only by design

Add a provider secret, save it, and the connections list only ever shows status and metadata afterward - never the value. This is the same guarantee the MCP connection credentials and Connected Apps OAuth secrets carry: whatever goes into the vault stays there.

The Secrets admin page with the provider credential vault
Keys go in. They never come back out through the API, even to an admin.