Secret Manager
Where credentials live: mail sender settings, single sign-on configuration, and the secrets integrations use.
A stored value can never be read back
You can replace a secret, but you cannot view it. The list shows only a fingerprint. If nobody knows the value any more, the only way forward is to replace it.
What is stored
| Column | Notes |
|---|---|
| Key | What it is called |
| Type | GRAPH, SSO, GITHUB, SFTP, AS2, S3 or OTHER |
| Scope | Platform or Domain |
| Domain | Which domain it belongs to |
| Value | The fingerprint, never the value |
| Expires | When it stops working, where that applies |
| Enabled | Whether it is in use |
| Updated by / Update date | Who last changed it |
Adding one
Create offers Graph email for your mail sender settings and SSO for single sign-on. As a domain administrator these are the two you manage, for your own domain.
If something is refused
| Message | Meaning |
|---|---|
| You don't have access to this. | Your authority does not cover that secret |
| Not found - it isn't set up yet, or was deleted. | Nothing is stored under that key |
| Already set up - edit it instead. | It exists; replace the value rather than creating it again |
| Server unavailable, try again shortly. | A temporary problem, not a configuration one |