Plaintext still works. SecretRefs are opt-in per credential.
Secrets pages
Where each section moved
Every section, tab, step, and accordion title from the previous single-page version keeps its anchor here, so an existing link such as/gateway/secrets#shared-secret-store still resolves. Each entry points at the
page that now holds the content.
- Runtime model
- Egress-time injection (sentinels)
- Agent-access boundary
- Active-surface filtering
- Gateway auth surface diagnostics
- Onboarding reference preflight
- SecretRef contract
- Provider config
- Shared secret store
- Secret egress proxy
- Traffic allowlist
- File-backed API keys
- Exec integration examples
- MCP server environment variables
- Sandbox SSH auth material
- Supported credential surface
- Required behavior and precedence
- Activation triggers
- Degraded and recovered signals
- Command-path resolution
- Audit and configure workflow
- One-way safety policy
- Legacy auth compatibility notes
- Control UI
- Egress-time injection (sentinels)
- Examples of inactive surfaces
- env
- file
- exec
- store
- Env provider
- File provider
- Exec provider
- Store provider
- 1Password
- Bitwarden Secrets Manager (
bws) - HashiCorp Vault CLI
- password-store (
pass) - sops
- Strict command paths
- Read-only command paths
- Audit current state
- Configure and apply SecretRefs
- Re-audit
- secrets audit
- secrets configure
- secrets apply
Related
- Authentication - auth setup
- CLI: secrets - CLI commands
- Vault SecretRefs - HashiCorp Vault provider setup
- Environment Variables - environment precedence
- SecretRef Credential Surface - credential surface
- Secrets Apply Plan Contract - plan contract details
- Security - security posture
- Configuration reference - where each secrets and env setting is documented
- Ask user - asking the operator a non-secret question; never answer it with a credential, use the masked
secretstool for those - Auth credential semantics - the canonical rules for auth profile ordering and runtime credential resolution