Your agent never sees the secret
The model driving your agent is never trusted with raw credentials, which could otherwise end up in a log, a memory file, or a message. A secret is stored encrypted and lives outside the agent’s reach. A proxy injects it into requests at the network layer. The agent gets the capability without holding the credential. The same principle applies to every connection on Skydive. See Permissioning for the full security model.When to use a secret
- A service offers an API key or token but not OAuth
- You have an internal API the agent should call
- A tool or MCP server needs a token to authenticate
How it works
You don’t have to set secrets up in advance. When a task calls for one, the agent presents a secure card for you to paste the key into. You can also offer one anytime by telling the agent you want to give it a credential.1
Add the secret
Paste the key into the secure card and name it, so the agent knows what it’s for.
2
It's stored, not shown
The value is encrypted at rest. The agent can reference it by name and use it, but never reads the plaintext.
3
Used on the wire
When the agent makes a request to that service, a proxy injects the credential into the request. The request authenticates correctly while the secret stays out of prompts and logs.
Managing secrets
Add, update, and remove secrets at any time. Rotate a key by updating its value. The agent picks up the new one on its next request. An agent’s Manage secrets panel supports bulk work. Add several keys at once: paste a whole.env block or import one from a file, and it splits into rows. Copy secrets out as KEY=value lines, or download the whole set as a .env file. Moving a group of credentials between agents is a single step.
Prefer OAuth where you can
One-click connections refresh themselves and are cleaner than manual keys.