For the complete documentation index, see llms.txt.
Skip to main content
Version: 8.10 (unreleased)

Configure credentials in the modeling interface

Select an existing credential on a connector task in the Camunda Hub modeling interface, or create a new one without leaving the properties panel.

note

This page covers credentials that authenticate connector tasks, such as an AWS Credential. It is unrelated to the client credentials required to deploy or run a process, which authenticate Camunda Hub against your cluster.

Select a credential​

Connectors that support credentials show a credential field in the properties panel, such as AWS Credential. Select the field to open the credential chooser, which lists the credentials deployed to the connected cluster that match the credential type the connector needs. On a Self-Managed cluster with several environments, the chooser also lists credentials deployed only to another environment on that cluster; those don't resolve at runtime in the environment you are connected to.

Selecting a credential stores only a reference to it in your diagram. The credential's values stay in the environment they were deployed to.

If no credential matches, the chooser tells you so by name, for example Cannot find AWS Credential with name AWS_PROD. This usually means the credential doesn't exist on the connected cluster, or it was created for a different credential type.

What you can do in the chooser​

What the chooser offers depends on whether you can edit the diagram, that is, whether you have edit access to the project.

SituationAvailable actions
You can edit the diagramSelect a credential, or create a new one.
You can edit the diagram, and the selected credential is compatibleSelect a credential, or edit the selected one.
You can edit the diagram, and the selected credential is out of dateSelect a credential, or upgrade the selected one.
You cannot edit the diagramSelect a credential only.

This only controls what the chooser offers. On the Credentials page, any member of your organization who has access to Camunda Hub can manage credentials, and the cluster's own authorizations apply whenever Hub writes a credential to it.

The chooser is unavailable while you aren't connected to an environment, while you work offline, while the connected environment is paused, or when it runs a Camunda version before 8.10. The field tells you which of these applies.

A connector declares the minimum credential version it needs. A newer credential always satisfies an older requirement, so upgrading is only needed when a credential is older than the connector requires.

Create a credential​

To create a credential from the properties panel:

  1. Open the credential field, then select the option to create a new credential.
  2. Enter a Credential name. Camunda Hub suggests a Credential ID based on the name.
  3. Change the Credential ID if you want a different one. You cannot change it after the credential is created.
  4. Fill in the fields for this credential type. For a sensitive field, enter a reference to a secret that already exists on the cluster, using camunda.secrets. followed by the secret key, such as camunda.secrets.AWS_SECRET_KEY. Select the field to pick from the secrets on the cluster behind the connected environment.
  5. Save the credential. Camunda Hub creates it in the connected environment and selects it on the connector task.

Camunda Hub highlights a sensitive field and warns you when its value is not a secret reference. Saving is still allowed, so replace the value with a reference to keep the sensitive value in the secrets vault. For the reference syntax, see reference a secret from a credential field.

Camunda Hub checks whether the secret you referenced exists on the cluster, without revealing its value. If the secret is missing, you see a warning, but you can still save the credential. The connector fails at runtime until the secret exists.

A value that embeds camunda.secrets. mid-word, such as foo.camunda.secrets.AWS_SECRET_KEY, holds no reference, so Camunda Hub reports it as plain text rather than as a missing secret. The plain-text warning replaces the missing secret warning on that field.

note

You cannot create the secret itself here. Add the secret to the cluster first in Connector secrets, then reference it from the credential.

A credential you create here is managed in Camunda Hub immediately. It appears on the Managed in Hub tab of the Credentials page.

Edit or upgrade a credential​

Editing a credential opens the same form, pre-filled with its current values. Saving replaces the credential's values in the environment, which takes effect immediately for every process that references it.

Upgrading a credential opens the same form and shows the fields that the newer credential version adds. Fill them in and save to make the credential usable with the connector version you are modeling against.

Additional resources​