Attach secrets and credentials to agents
You can now give an agent credentials without pasting them into chat. Create a secret or attach one you've already saved, then let the agent use it for the task.
Attach a credential
Open Advanced in your agent's configuration, then Custom secrets, and click Attach. Choose an existing secret, or choose + New secret to enter a name and value.
Set the environment variable the tool expects, such as SERVICE_API_TOKEN, and attach it. The agent can use the credential on its next turn. Save or discard any unsaved changes to the agent first; Attach is disabled while the configuration has unsaved edits. You can refer to the variable in your instructions without sharing the value in chat.
Add a secret when the agent asks
If the agent needs a credential during a task, it can ask you to configure one. Click Configure on the request card, then create or select the secret and attach it. Don't paste the credential into your reply.
The saved value can't be read back through the product. Code running for the agent can access an attached credential to use it, so only attach the credentials it needs. Removing an attachment doesn't revoke the credential at its provider.