Skip to main content
OpenClaw supports additive SecretRefs so supported credentials do not need to live as plaintext in configuration.
Plaintext still works. SecretRefs are opt-in per credential.
Plaintext credentials remain agent-readable when they sit in files the agent can inspect, including openclaw.json, .env, retired auth-profile JSON archives, or generated agents/*/agent/models.json files. SecretRefs reduce that local blast radius once every supported credential is migrated and openclaw secrets audit --check reports no plaintext residue.
This page is an index. Secrets management is documented on five pages, one per reader job. Open the page that matches your task.

Secrets pages

Where each section moved

Every section, tab, step, and accordion title from the previous single-page version keeps its anchor here, so an existing link such as /gateway/secrets#shared-secret-store still resolves. Each entry points at the page that now holds the content.