Skip to main content
Monk runs your app in your own cloud account, so it needs credentials for that account and for any services your app uses. You don’t have to set anything up in advance. When a plan needs a credential, Monk opens a form in the local dashboard and you enter it there.

Where credentials go

  • You type, upload or authorize credentials in a local dashboard form, never in the chat. The coding agent never sees the values.
  • Monk stores them in your OS keychain (or an encrypted file where there is no keychain) and pushes them to your cluster when a deployment needs them.
  • You can see what is stored, without the values, under Vault in the local dashboard.
See Security for the full picture.

Clouds

AWS

IAM access key ID and secret access key

Google Cloud

Service account JSON key file

Microsoft Azure

Service principal, as fields or an SDK auth JSON file

DigitalOcean

Personal access token

Hetzner

API token

Services

Monk asks for these the first time a plan uses the service.

Netlify

The form offers a Netlify sign-in. If you prefer a token, create a personal access token in Netlify under User settings → Applications and paste it.

MongoDB Atlas

The form offers an Atlas sign-in. To enter values instead, create a service account in your Atlas organization’s access manager and paste its client ID and client secret. The organization name is optional.

Vercel

Create a token at vercel.com/account/tokens. Add a team ID if you deploy to a team.

Auth0

In your Auth0 tenant, create a machine-to-machine application authorized for the Management API. Enter the tenant domain, client ID and client secret.

Redis Cloud

Copy the account key and a user key from the API keys page in Redis Cloud. Choose a database password or let the form generate one.

GitHub for CI/CD

CI/CD setup creates a GitHub Actions workflow in your repository, so it needs a GitHub token.
  1. In GitHub, open Settings → Developer settings → Personal access tokens → Fine-grained tokens (direct link).
  2. Give it access to the repository you deploy from.
  3. Grant these repository permissions: Actions (read and write), Secrets (read and write), Environments (read and write), Contents (read) and Metadata (read).
  4. Generate the token and paste it into the form when Monk asks. You can also set a default repository in owner/repo form.

Slack for Watcher alerts

Watcher posts alerts to Slack through an incoming webhook.
  1. Go to api.slack.com/apps and create an app from scratch in your workspace.
  2. Open Incoming Webhooks and turn them on.
  3. Click Add New Webhook to Workspace and pick the channel for alerts.
  4. Copy the webhook URL (it starts with https://hooks.slack.com/services/) and paste it into the form when Monk asks.
Slack only receives alerts. You can’t chat with Monk or approve anything from Slack.

Managing credentials

Ask your agent, and Monk opens the form when one is needed:

Good practice

  • Create a dedicated user, service account or service principal for Monk instead of using your personal or root credentials. Each cloud page lists the permissions it needs.
  • Rotate keys on your usual schedule, and straight away if one may have leaked.
  • Turn on MFA for the accounts that manage these credentials.

First deployment

See where the credentials form appears in a deployment