Provider vault

In the local app, there will be no vault because Pi will use its credential store on the machine. Pi will read the user’s own provider credential, which will stay on the machine. In the paid console, the owner will store each provider key once. The console will encrypt it at rest, and every paid route will use it. No user machine will hold a company key.

This model will be available at launch. The rest of this guide describes the paid console. Owners with console access can add a provider credential, see its versions, and revoke it today.

Manage provider credentials

In the paid console, open Providers.

  1. Choose Add provider.
  2. Enter a Label.
  3. Select the Provider.
  4. Complete the provider’s settings.
  5. Enter the credential in API key or bearer API key.
  6. Choose Connect and validate.

The console encrypts the credential when you submit it and never shows it again.

The Credential versions table shows each version and its status.

  1. To revoke a version, choose Revoke on its row.
  2. Review the version.
  3. Choose Revoke credential version.

The console stops using that version for provider requests. Revocation in the console does not delete the key from the provider’s systems.

Encryption key rotation

Encryption key rotation will be available at launch. The console will rotate the encryption key that protects your stored provider credentials. You will not need to enter each provider credential again.

The console will resume interrupted work and keep the old encryption key until the rotation completes and checks pass. The encrypted provider credentials will stay unchanged.

Cloud key service

A cloud key service will be available at launch. The console will move encryption key protection to AWS KMS for the owner. The encrypted provider credentials will stay unchanged, so you will not need to enter them again.

The console will retain the existing encryption keys until the move completes and checks pass. Owners cannot start encryption key rotation or the move to AWS KMS in the console today.

Search docs

Join the waitlist

Get desktop release updates.

We will email you about desktop releases and new features. muniment is a desktop workspace for your models, tools, and files.