Administration Secrets

Secrets

Per-tenant provider credentials — write-only, vault-encrypted, injected at the chokepoint. Your code never sees them.

Forgebench stores your OpenAI, Anthropic or Gemini credential once, encrypted, and injects it into the outbound call at the chokepoint. Your agent code authenticates to Forgebench with its own key (see API keys) — never with the provider's. Revoking a compromised provider credential is one action on this page, not a redeploy of everything that used it.

Using Google Vertex AI? It takes a service-account JSON rather than a single API key; see Google Vertex AI for the setup.

Write-only, by design

PropertyWhat it means
Vault-encryptedThe secret is encrypted at rest with a tenant-bound envelope.
Write-onlyThe API reports which providers are configured, never the key material itself — not to you, not to an admin, not on a second read.
Injected at call timeThe chokepoint attaches the credential to the provider request server-side. Your request and your logs never carry it.
AuditedSetting or removing a credential writes an immutable audit row — see Audit.
One row per provider. The secret column never shows the key, only that a vault entry exists.
One row per provider. The secret column never shows the key, only that a vault entry exists.

A Coverage panel sums up the whole workspace at a glance: how many providers are configured out of the catalog, how many models that makes reachable, and how many are stranded — cataloged but unreachable because no provider on the list needing them has a credential yet.

Add a credential

  1. Open Secrets

    In the sidebar, expand Admin and choose Secrets.

  2. Choose a provider

    The list is driven by the gateway's own model catalog, so it only offers providers Forgebench can actually route to — not a fixed guess.

  3. Paste the key and store it

    The value is sent once and never echoed back. If you lose track of what you pasted, you cannot recover it here — only replace it.

Add provider credential — the key is write-only from the moment it's pasted
Add provider credential — the key is write-only from the moment it's pasted

Adding or replacing a provider credential requires the admin role.

Removing a credential

Removal is type-to-confirm: type the provider's name to enable the button. This is permanent — any call that needs that provider fails at the chokepoint until a new key is stored. It writes its own audit row, same as adding one.

Next