Secrets

Track credential exposure and rotation risk across OAuth clients, keys, and tokens.

Identity & access

The Secrets page (admin/auditor only) surfaces credential exposure risk across OAuth clients, service-account keys, API keys, and domain-delegation grants. A risk-distribution bar and an overdue-rotation panel sit above a paginated inventory showing each secret's name, type, status, risk score, last-rotated date, and rotation cadence. A second tab manages tenant API tokens.

How to use it

  1. Open Secrets & API Tokens from the sidebar.

  2. Read the risk-distribution bar for the critical/high/medium/low split.

  3. Check the rotation-overdue panel to find secrets past their cadence.

  4. Filter the inventory by status (All / Active / Inactive) and page through to review risk scores and last-rotated dates.

  5. Switch to the API Tokens tab to create or revoke tenant tokens (see the API tokens guide).

Tips

  • The Secrets inventory is limited to admin and auditor roles.

Open Secrets in the app

Jump straight to the feature, or browse the rest of the guides.