Create a Variable
Open the Variables section and define a key, add an optional description, set the type — text or secret — and enter the value.
Define API keys, tokens, and configuration values once. Reference them securely across every integration and connection in your digital workforce — no copying, no exposure, no drift.
Every new connector, tool, and webhook needs credentials. Pasted in one at a time, those values spread across configurations faster than anyone can track them.
Credentials you cannot see are credentials you cannot govern.
When an API key is pasted into six different configurations, rotating it means finding and updating all six. Miss one, and something breaks.
Sharing a token by email or chat exposes it everywhere it was forwarded. Once it's out, you can't tell who has it.
When a credential changes and something goes wrong, it's nearly impossible to know what depended on the old value — until after the fact.
A Variable is a named, versioned, permission-controlled value stored securely in Opal. Set the value once and reference it across every Connector, Tool, and Webhook that needs it.
Every Variable has a key — the name used to reference it — and a value: the actual credential, token, or configuration string your integrations need.
Set the type based on how sensitive the value is. Text values are visible to authorized users. Secret values are protected after they are saved, so team members can use them without seeing the raw value.
Reference a Variable when configuring MCP Connections, Tool Definitions, and Webhooks — no copying, no paste errors.
See everywhere a Variable is referenced, in real time. Before rotating a credential, review what depends on it so nothing breaks unexpectedly.
Changes to a Variable's value are recorded over time, giving teams a clear record of what changed and when.
Control who can view, edit, or manage each Variable. Not everyone who uses an integration needs access to the credentials that power it.
Open the Variables section and define a key, add an optional description, set the type — text or secret — and enter the value.
When configuring an MCP Connection, Tool Definition, or Webhook, reference the Variable instead of pasting the raw value.
Team members can use the Variable across configurations without ever seeing the underlying secret.
Open the Linked Resources panel to see every place the Variable is referenced before rotating or updating a value.
When a credential changes, update the Variable in one place. Every resource that references it reflects the new value immediately.
Define a value once and reference it everywhere it is needed. Eliminate duplicates and the errors that come with them.
Choose the secret type for sensitive values. Team members can use them in configurations without ever seeing the raw credential.
Variables are built to work directly with Connectors (MCP Connections), Tools, and Webhooks — the three places integrations need credentials.
The Linked Resources panel shows what depends on each Variable, so teams can assess the effect of a change before they make it.
Version tracking records every change, giving teams a clear, verifiable history of how credentials and configuration values have evolved.
Rotation, shared access, and new integrations — handled from a single, governed source of truth.
A platform administrator manages a dozen agents and integrations that connect to an external analytics service. Rather than tracking down where the API key was pasted, she defined it as a Variable from the start. When the key needs to rotate, she opens the Variable, reviews the Linked Resources panel to confirm what is affected, updates the value once, and the entire platform updates automatically.
A technical lead needs three agents and two webhooks to call a payment service — but cannot share the API token in a message. He creates a Variable with the secret type, sets permissions so the relevant team members can use it without seeing the raw value, and references it in each configuration. The token is never sent in a message, pasted in a document, or emailed.
A builder is setting up a new Connector to a CRM the organization just adopted. She creates a Variable for the API key, references it in the MCP Connection configuration, and adds a note in the description. When a colleague needs to set up a second connection to the same CRM six months later, the Variable already exists — same key, right description, one source of truth.
Permissions on each Variable control who can view, edit, and manage it — independent of the integrations that reference it.
Values set to the secret type are protected after saving. Visible in use, never exposed in the interface.
All changes to Variable values are tracked over time, providing a clear audit trail for every credential and configuration value.
ZDR is enabled automatically when models and providers that support it are used through Connectors and Tools.
ISO 27001, ISO 42001, and SOC 2 Type II certifications are underway.
Store keys, tokens, and configuration values once, reference them everywhere, and rotate them without breaking a single Connector, Tool, or Webhook.