Security and secrets

July 29, 2026 ยท View on GitHub

Keep API keys, provider credentials, and signing secrets in the Conductor server or its configured secret provider (SecretClient, AuthorizationClient, IntegrationClient). Do not put them in workflow input, agent prompts, task output, example source, or version control.

Agent tools declare required credentials via credentials: [...]; a capable server delivers resolved values only in the polled task's runtimeMetadata, fail-closed โ€” a tool whose declared credential wasn't delivered fails non-retryably naming the missing credential, with no ambient-env fallback. See agent tools.

There is no dedicated security.md/secret-client.md API reference page yet (tracked in documentation-parity.md); see the secrets and authorization API journey examples for a runnable walkthrough in the meantime.