# Credentials and integrations (https://optakt.ai/docs/credentials)

## Credentials stay sealed [#credentials-stay-sealed]

API keys, tokens and passwords are kept in a vault on your agent's machine, encrypted, and belong to one [agent scope](/docs/spaces). Your agent uses a credential by its name inside the command that needs it. The value is filled in for that command, rather than being given to the model as setup data. Keep commands and connected tools from printing credentials: their output can enter the conversation.

## Adding a credential [#adding-a-credential]

- **In the admin app:** open Secrets, press `c`, and enter a name and the value.
- **By signing in:** for services with a sign-in flow, your agent starts it and sends you a link or a code. You approve on your own device; the token goes straight into the vault.

Never paste a credential into the chat. A message is stored in the history and sent to your model provider.

## Integrations [#integrations]

There is no catalogue of integrations to install. Add a credential, then ask your agent to learn the service: it reads the service's documentation, tries it, and writes down how it works in its memory. From then on it uses it whenever a job needs it. You just built your own integration.

## Locked and unlocked [#locked-and-unlocked]

A new credential is **unlocked**: your agent can use it at any time, across restarts.

A **locked** credential stays sealed until an admin of the scope unlocks it. Under Secrets, `l` locks and `u` unlocks; `a` selects all of them first. An admin session remembered by the app is not an open vault: after a timeout, logout or service restart, an unlock asks for the admin's password again.

## Managing them [#managing-them]

Under Secrets you can also replace a value (`p`), rename (`n`) and destroy (`d`). The credentials of Telegram, model providers, Voyage AI and ElevenLabs are managed under Integrations.
