Managing Secrets & API Keys
Published February 27, 2026 · Last updated June 17, 2026 · 4 min read
Managing Secrets & API Keys
Save API keys, tokens, passwords, and other credentials securely in Obvious. Add a credential yourself or use the secure form when an agent asks, then control who can use it and whether its use needs your approval.
Add a credential yourself
If you already have the credential you want to save, add it in Settings.
-
Open Settings → Integrations → Secrets.
-
Select Add secret.
-
Enter a Name, such as
STRIPE_API_KEYorDATABASE_URL. -
Enter the secret Value.
-
If Available to appears, choose who should be able to use the credential.
-
Select Add secret.
Credentials added in Settings use Regular access, so agents can use the credential without asking you each time. If you want to review and approve each use, edit the credential and change Access tier to Protected. You can switch tiers later if your security needs change.
Use the secure form when an agent asks
If an agent needs a credential that is not saved yet, it presents a secure request form in the chat. For example, an agent connecting to Stripe may request a Stripe API key. Enter the credential in the form instead of typing it into a normal chat message. The form saves the value securely and returns the agent to its work without displaying the value in the conversation.
The secure credential request form can request one or more fields. For each field, choose Regular or Protected under Tier. You'll see Available to when your workspace role and available sharing options let you choose who can use the credential. Choose who can use the credential, then submit the form.
Choose who can use the credential
When Available to appears, choose the narrowest group that needs the credential. You may not see every option below. The choices available to you depend on your role, memberships, and the teams and projects available to you.
| Option | Who can use it |
|---|---|
| Only me (all workspaces) | Only you. Other workspace members cannot see or use it. |
| Team members | Members of the selected team. |
| Workspace members | Members of the selected workspace. Only workspace owners and admins can create this scope. |
| Project members | Members of the selected project. |
Choose Regular or Protected access
Choose the access tier that matches how you want the credential to be used.
| Access tier | What it means |
|---|---|
| Regular | Agents can use the credential automatically, without asking you each time. |
| Protected | Each use requires your approval. The agent pauses and waits until you approve or deny the request in your inbox. |
If you're not sure which tier to use, start with Protected. You can always switch a credential to Regular later once you've confirmed how an agent uses it.
Approve or deny Protected use
When an agent needs a Protected credential, it pauses and sends an approval request to your inbox. Open the request to see which credential the agent wants to use and why. Select Approve to let the agent continue, or Deny to stop the use and send the agent back to you.
Approvals are one-time. Each time a Protected credential is needed, a new approval request appears. If you find you're approving the same credential repeatedly for a trusted agent, switch the credential to Regular access.
Update or remove a saved credential
To edit or delete a credential, open Settings → Integrations → Secrets, find the credential in the list, and select the options menu next to it. You can update the name, value, or access tier, or delete the credential entirely. Deleting a credential is permanent — any agent or workflow that relied on it will stop working until you add a replacement.
Keep credentials safe
-
Enter credentials only in the secure form or in Settings → Integrations → Secrets. Never paste a secret into a regular chat message — it will be visible in the conversation history.
-
Use Protected access for credentials that have broad access, such as workspace-scoped API keys for payment processors or production databases.
-
Review your saved credentials periodically and remove any that are no longer in use.