Documentation Secrets and Security

Prepare credentials for synchronization

Prepare owners, environments, targets, and rotation expectations before secret synchronization.

Prepare credentials before connecting or promoting a workflow. A clear ownership and rotation plan prevents a structurally valid workflow from failing in its target environment.

Preparation checklist

  • Identify the system the workflow must access.
  • Name the credential owner and a backup owner.
  • Create separate Development, Staging, and Production credentials when supported.
  • Limit each credential to the required operations and resources.
  • Confirm the target environment has the matching credential reference.
  • Record the rotation procedure and expected expiration date in your approved system of record.
  • Define how the workflow will be tested after rotation.

Use stable references

Keep credential references predictable across workflow versions. Do not rename or delete a reference until you have checked every workflow and environment that uses it.

Before synchronization

Confirm the destination, credential type, owner, and intended reference. Review the request without sharing the value with unauthorized users. If an approval is required, wait for that approval before changing the target.

After synchronization

Confirm the status and timestamp, then perform a limited validation appropriate for the integration. A successful synchronization confirms delivery; it does not prove that the external service granted the intended permissions.

If the credential fails

Check expiration, scope, external-service authorization, target environment, and reference mapping. Preserve the safe error reference and timestamp. Never copy the secret value into a ticket, chat, screenshot, or log.