Credentials
Securely acquire, store, rotate, select, and use external authority from Constal agents.
Constal separates who may invoke an Agent from what external authority the Agent may use. An Auth Provider authenticates an incoming caller. A Credential Provider acquires and maintains outbound secret material. A Credential stores that material as governed versions. A scoped binding selects the correct Resource or Credential for the authenticated tenant, customer, or principal.
Choose a path
| What you need | Start here |
|---|---|
| Store an API key, token, password, or signing secret you already have | Store an existing secret |
| Let a person grant access through OAuth | Authorize an OAuth credential |
| Run unattended automation with application or installation authority | Choose an authentication model |
| Serve multiple customers or users from one agent | Scoped bindings |
| Build a custom acquisition and rotation lifecycle | Build a Credential Provider |
| Diagnose a failed setup, renewal, or authorization | Troubleshooting |
Choose an interface
| Interface | Use it for |
|---|---|
| Console | Interactive provider installation, authorization, lifecycle, and binding management |
| SDK | Authoring a provider lifecycle or consuming a governed Resource from Agent code |
| CLI | Secure, repeatable Credential and scoped-binding administration |
| Platform API | Application-owned provider setup and Credential lifecycle workflows |
Mental model
Credential Provider → creates and maintains → Credential
Resource → consumes → Credential
Scoped binding → selects → Resource or Credential
Agent → invokes → ResourceA Credential is deliberately opaque. Constal encrypts and versions its material, but only the consuming integration decides whether the bytes represent an API key, OAuth token, private key, password, or another secret.
Common examples
- A tenant-wide model gateway uses one imported API-key Credential.
- A customer-scoped GitHub Resource uses that customer's GitHub App installation Credential.
- A principal-scoped GitHub Resource uses the signed-in person's OAuth Credential.
- A Credential Provider uses a bootstrap Credential, such as an application client secret, to create many output Credentials.
Next steps
Read the complete mental model, then follow the guide matching your authentication model. If an agent serves multiple owners, read scoped bindings before deploying its Resource selectors.