Browse documentation

Vaults

Store the credentials agents need securely in a vault.

When an agent uses a connector to reach an outside service, it needs credentials: an API key, an OAuth grant, or a service account key. Those credentials live in a vault. The agent is bound to a vault and reads from it at run time, so secrets never have to be pasted into the agent itself.

Open the Vaults page

  1. In the left sidebar, open the Settings tab.
  2. Under Agent, select Vaults.

The page has two sections:

  • Personal vault: your private vault. Credentials stored here are visible only to you.
  • Shared vaults: vaults teammates can reuse across their agents.

Each vault shows how many credentials and how many agents it holds, with a Personal or Shared badge.

The Vaults page with a Personal vault section and a Shared vaults section, each vault showing its credential and agent counts.
The Vaults page: your Personal vault, and any Shared vaults for the team.

Create a shared vault

  1. On the Vaults page, click Create shared vault.
  2. Give it a Name and an optional Description.
  3. Click Create. Spark drops you straight into the new vault so you can add credentials.
The Create shared vault dialog with Name and Description fields.
The Create shared vault dialog: name it and add an optional description.

Add a credential

  1. Open a vault (from its more menu (⋮), choose Edit).
  2. In the Credentials section, click Add credential and pick a connector.
  3. In the Connect dialog, provide the credential.

What the dialog asks for depends on how the connector authenticates, and a badge on the dialog says which it is:

MethodWhat you provide
OAuth 2.0One click through Spark's managed app, or your own Client ID and Client Secret
API KeyThe key, pasted
Service accountA JSON key, pasted

Connect an account walks through each one, including which redirect URI to register when you bring your own OAuth app.

Only active connectors that need credentials can be added. Opening the dialog from outside a vault adds a picker so you can choose which vault stores the credential.

The Connect dialog for an API-key connector, with a masked API Key field and a Save button.
An API-key connector: paste the key, then Save it into the vault.

Bind a vault to an agent

In the agent editor, use the Vault field to choose which vault the agent reads from. If any of the agent's tools come from a connector that needs credentials, a vault is required. The vault's detail page also lists the Agents using this vault, so you can see what depends on it.

The agent editor's Vault field open, listing the Personal and Shared vaults to choose from.
The agent editor's Vault field: pick the vault the agent reads credentials from.
Use a personal vault for credentials only you should hold, and a shared vault when several teammates or agents need the same access. Anything in a shared vault is usable by every agent bound to it, so put a connection there when you want it reused and in your personal vault when you do not.

OAuth connections stay live on their own

An OAuth connection does not need re-authorizing for each agent, or again when its token expires. Spark holds the connection centrally and issues a fresh token whenever an agent runs, so one connection serves every agent bound to that vault.

Where to go next