Skip to main content
Cedros

Storing credentials in Cedros Vault

Save passwords and API keys in Cedros Vault, organize credentials, replace secrets, and recover earlier values.

Use Vault to keep passwords, API keys, and other credentials in one place. You can save an item for yourself, find it later, and update its details or secret without creating a duplicate.

Open Tools → Vault in the admin area. You need access to Vault; your role also determines which credentials you can see or change. If the tool is missing, ask your administrator to check your feature access.

Set up Vault and choose a collection

If the page shows Set up your vault, an administrator needs to select Set up vault. Wait for Vault is ready. Setup creates the Personal, Team, and Assistant collections. If the page instead reports a loading or connection error, resolve that error before treating the Vault as empty.

Choose a collection based on who should use the credential:

  • Personal: store credentials for your own use. Personal items stay private to your signed-in identity and cannot be shared with the team or assistant.
  • Team: organize shared credentials. An administrator manages these items; their access settings determine whether team members can read them.
  • Assistant: organize credentials intended for assistant use. The collection name alone does not grant the assistant access.

Administrators can read shared items. For those items, check Who can read it and the sharing controls rather than relying on the collection name. Keep team and assistant access off unless that access is needed.

Create a credential

  1. Select New credential.
  2. Enter a recognizable Name, such as “Newsletter service — production”. The name is visible in the list, so do not put the secret itself there.
  3. Paste the password or API key into Secret.
  4. Choose a Collection. Use Personal for your own credential. If you choose a shared collection, review Your team can read it and The site assistant can read it before saving.
  5. Select Create credential. Correct any field errors, then wait for Credential created.
  6. Review the saved item. Use Back to Vault to confirm that it appears in the list with the intended collection and audience.

Cancel closes an unsaved new credential without creating it. Creating a Vault item stores the value you provide; it does not create an account at the service or verify that the password or key works.

If you are connecting a service to Cedros, follow its setup instructions as well. Connecting and managing service providers explains where to configure and test those connections.

Find, reveal, or copy a secret

Use Filter credentials… to search by name, description, or collection. Clear the search to return to all items available to your account. You can also sort the list by Name, Collection, Who can read it, or Updated.

Open the credential you need. Its Secret stays masked until you select Reveal. Once revealed, Copy copies the value and Hide masks it again. Reveal only when you need the value, and keep it out of screenshots, ordinary notes, and support messages.

View-only access can still let you reveal a credential that has been shared with you. It does not let you replace the secret or change its details.

Edit the name, description, or collection

Open the credential and find Details. Change Name, Collection, or Description, then select Save. Wait for Item saved and check the updated details. Discard returns unsaved detail edits to their saved values.

Use the description for context such as the account, purpose, or environment. It appears in the credential list, so keep the secret in the Secret card.

Changing collections can change who is allowed to use an item. Moving an item into Personal removes team and assistant sharing. Moving a Personal item into a shared collection makes it available to administrators and requires permission to manage shared credentials. Review Who can read it after saving a move.

The cards save separately: Save in Details saves the name, description, and collection. Replacing a secret has its own confirmation. Sharing switches on an existing shared item apply immediately, so do not change them as part of a trial edit you intend to discard.

Replace a password or API key

  1. Open the credential and select Replace in the Secret card.
  2. Enter the replacement in New secret.
  3. Select Replace secret and wait for Secret saved. If the save fails, read the error; the replacement field stays open so you can retry.
  4. Check that the service or workflow using this credential has the correct current value.

Use Cancel to discard an unsaved replacement. A successful replacement changes the stored Vault value; it does not change a password at the original service or revoke an old API key. Make any required change at that service too.

An item marked Needs setup has not finished storing its secret. Open it with Set up, choose Add secret, enter the value, and select Save secret. Confirm that the setup warning clears before relying on the item.

Recover an earlier secret or a trashed item

If you replaced a secret by mistake and have permission to edit the item, open Version history and select View version history. Choose the appropriate Recover version action, review the confirmation, then select Recover secret. Use Load older versions if more history is available.

Recovery replaces the stored secret while keeping the current sharing and usage restrictions. The value it replaces remains in version history. Recovering an old password or key does not make it valid again if the original service has changed or revoked it.

To remove an item from the active list, open its actions menu and select Move to trash. This moves it to recoverable trash. To undo that, open Trash from the Vault list and select Restore beside the item, then return with Back to all items. The Trash button appears when recoverable items are available.

Moving an item to trash does not revoke the credential at its original service. Revoke it there separately if it should no longer work.

Resolve common problems

I cannot create or edit an item. Check whether you have view-only access. You may be able to manage your own Personal items while shared items require an administrator. If Set up vault is missing from the setup screen, ask an administrator to complete setup.

Create credential reports missing information. Enter a Name and Secret and choose a Collection. Shared credentials require permission to manage that collection. Read any returned error before trying again.

Save is disabled in Details. Make a change and check that Name and Collection are filled in. Use the Secret card's controls when you want to replace the stored value.

An item is missing. Clear the filter, check Trash, and confirm that you are signed in with the account that owns or can read the item. A loading error is not proof that credentials were deleted. Use Try again for a Vault loading error or Retry trash if only trash failed to load.

A save, restore, or recovery reports a conflict. The item may have changed since you opened it. Reload its current state, review what changed, and retry only the change you still intend to make. Do not assume an error means the action succeeded.