Where credentials go
- You type, upload or authorize credentials in a local dashboard form, never in the chat. The coding agent never sees the values.
- Monk stores them in your OS keychain (or an encrypted file where there is no keychain) and pushes them to your cluster when a deployment needs them.
- You can see what is stored, without the values, under Vault in the local dashboard.
Clouds
AWS
IAM access key ID and secret access key
Google Cloud
Service account JSON key file
Microsoft Azure
Service principal, as fields or an SDK auth JSON file
DigitalOcean
Personal access token
Hetzner
API token
Services
Monk asks for these the first time a plan uses the service.Netlify
The form offers a Netlify sign-in. If you prefer a token, create a personal access token in Netlify under User settings → Applications and paste it.MongoDB Atlas
The form offers an Atlas sign-in. To enter values instead, create a service account in your Atlas organization’s access manager and paste its client ID and client secret. The organization name is optional.Vercel
Create a token at vercel.com/account/tokens. Add a team ID if you deploy to a team.Auth0
In your Auth0 tenant, create a machine-to-machine application authorized for the Management API. Enter the tenant domain, client ID and client secret.Redis Cloud
Copy the account key and a user key from the API keys page in Redis Cloud. Choose a database password or let the form generate one.GitHub for CI/CD
CI/CD setup creates a GitHub Actions workflow in your repository, so it needs a GitHub token.- In GitHub, open Settings → Developer settings → Personal access tokens → Fine-grained tokens (direct link).
- Give it access to the repository you deploy from.
- Grant these repository permissions: Actions (read and write), Secrets (read and write), Environments (read and write), Contents (read) and Metadata (read).
- Generate the token and paste it into the form when Monk asks. You can also set a default repository in
owner/repoform.
Slack for Watcher alerts
Watcher posts alerts to Slack through an incoming webhook.- Go to api.slack.com/apps and create an app from scratch in your workspace.
- Open Incoming Webhooks and turn them on.
- Click Add New Webhook to Workspace and pick the channel for alerts.
- Copy the webhook URL (it starts with
https://hooks.slack.com/services/) and paste it into the form when Monk asks.
Managing credentials
Ask your agent, and Monk opens the form when one is needed:Good practice
- Create a dedicated user, service account or service principal for Monk instead of using your personal or root credentials. Each cloud page lists the permissions it needs.
- Rotate keys on your usual schedule, and straight away if one may have leaked.
- Turn on MFA for the accounts that manage these credentials.
First deployment
See where the credentials form appears in a deployment

