Configure and grant a credential
- Open Studio → Monad Agent Runtime → Credentials.
- Create a credential with a label, an environment-variable name, the secret, and one or more exact DNS hostnames. Schemes, ports, paths, IP addresses, and wildcards are rejected.
- Open Studio → Monad Agent Runtime → Agents, edit an agent, and grant the credential from its Sandbox settings.
-
In generated Code Act or shell code, use the ordinary environment variable:
Protected execution
For credentialed execution, Monad:- injects a per-run sentinel instead of the secret;
- starts a protected local proxy;
- substitutes the real value only for exact configured hosts;
- redacts the secret from bidirectional traffic and tool results;
- prevents agent tools from reading
auth.jsonor the credential directory; and - fails before process launch when the required sandbox, TLS, or proxy containment is unavailable.
Storage boundary
auth.json version 1 contains only Agent Runtime Credentials. It is owner-only and is
inside the credential vault denied to agent filesystem tools. Agent records store
only credential IDs.
Native credentials are deliberately outside this mechanism:
Native credential settings use their direct value.
${secret:...} references are no
longer supported.
Breaking migration from legacy auth.json
There is no compatibility reader or automatic migration. Anauth.json using the
legacy credential-pool shape causes startup validation to fail so secrets cannot be
silently reinterpreted.
For a development home:
- Stop its daemon and back up the complete config directory.
-
Re-enter provider, channel, MCP, peer, Monadix, registry, and native-agent
credentials in their owning Studio or CLI settings. Do not copy
${secret:...}references. -
Replace
auth.jsonwith the current version 1 shape below, or let a fresh Monad home create it: - Create Agent Runtime Credentials in Studio and grant them to agents explicitly.
- Start the daemon and verify provider connectivity and any native integrations.
credentials object. Doing so would
incorrectly expose native authentication as an agent-execution capability.
Repository contributors can use the development migration reference for provider, agent, channel, and peer examples.