openclaw/docs/gateway/secrets.md
Vincent Koc 47ff7bfb11
docs: close remaining cross-link gaps across concepts, gateway, and security (#143923)
Adds the missing reciprocal links and one mis-targeted link fix for the
last open `link` audit findings.

- Related back-links: system prompt (context engine, timezone), diagnostics
  flags (gateway diagnostics, gateway troubleshooting), cloud workers
  (operator scopes), auth credential semantics (secrets, auth storage),
  agent runtime architecture (agent runtimes), agent runtime workflow
  (testing), network (remote access, architecture), threat model (gateway
  security index, network proxy), backups/updating/doctor (database schemas).
- docs/security/network-proxy.md gains a Related section.
- docs/security/incident-response.md links back to the three sibling pages
  that already link to it.
- docs/concepts/typing-indicators.md links the heartbeat and groups pages
  that its Defaults section describes.
- docs/diagnostics/flags.md links the environment-variable reference from
  the timeline section that names three OPENCLAW_DIAGNOSTICS_* variables.
- docs/concepts/main-session.md names `session.maintenance.maxDiskBytes` and
  links the maintenance reference instead of stating a bare 10 GB default.
- docs/network.md pointed its "Gateway config reference" entry at
  /gateway/configuration; retargeted to /gateway/configuration-reference.
- docs/openclaw-agent-runtime.md merges its References list into Related and
  keeps the old `#references` anchor as a stub.
- Six zh-CN glossary sources added beside their related existing terms.
2026-09-10 18:34:34 +08:00

8.8 KiB

summary read_when title sidebarTitle
Secrets management: SecretRef contract, shared secret store, runtime snapshots, and safe one-way scrubbing
Configuring SecretRefs for provider credentials and SQLite auth-profile refs
Storing team-wide secrets and environment values in the shared SQLite store
Operating secrets reload, audit, configure, and apply safely in production
Understanding startup fail-fast, inactive-surface filtering, and last-known-good behavior
Secrets management Secrets management

OpenClaw supports additive SecretRefs so supported credentials do not need to live as plaintext in configuration.

Plaintext still works. SecretRefs are opt-in per credential. Plaintext credentials remain agent-readable when they sit in files the agent can inspect, including `openclaw.json`, `.env`, retired auth-profile JSON archives, or generated `agents/*/agent/models.json` files. SecretRefs reduce that local blast radius once every supported credential is migrated and `openclaw secrets audit --check` reports no plaintext residue.

This page is an index. Secrets management is documented on five pages, one per reader job. Open the page that matches your task.

Secrets pages

Page Read it when
Secrets runtime model Owner isolation, sentinel injection, the agent-access boundary, and active-surface filtering.
SecretRef contract and provider config The SecretRef contract, id grammars, validation rules, and the env, file, exec, and store provider blocks.
Shared secret store and egress proxy The shared secret store, the secret egress proxy and its traffic allowlist, and file-backed API keys.
Secrets integration examples Exec provider recipes for 1Password, Bitwarden, Vault, pass, and sops, plus MCP and sandbox SSH.
Secrets operations and behavior Supported surfaces, precedence, activation triggers, degraded signals, and the audit and configure workflow.

Where each section moved

Every section, tab, step, and accordion title from the previous single-page version keeps its anchor here, so an existing link such as /gateway/secrets#shared-secret-store still resolves. Each entry points at the page that now holds the content.