Watch the Opal launch video
Variables

One place for every credential your platform needs.

Define API keys, tokens, and configuration values once. Reference them securely across every integration and connection in your digital workforce — no copying, no exposure, no drift.

Variablesone source of truth
ANALYTICS_API_KEY
•••••••••••• · 6 linked resources
secret
CRM_BASE_URL
value visible · 2 linked resources
text
PAYMENTS_TOKEN
•••••••••••• · 5 linked resources
secret
REGION_DEFAULT
value visible · 3 linked resources
text
connector · mcpreferenced
tool · definitionreferenced
webhook · payoutreferenced
The problem

Configuration chaos grows with every integration.

Every new connector, tool, and webhook needs credentials. Pasted in one at a time, those values spread across configurations faster than anyone can track them.

Credentials you cannot see are credentials you cannot govern.

01

Repeated secrets, compounding risk

When an API key is pasted into six different configurations, rotating it means finding and updating all six. Miss one, and something breaks.

02

Credentials in the open

Sharing a token by email or chat exposes it everywhere it was forwarded. Once it's out, you can't tell who has it.

03

No visibility into usage

When a credential changes and something goes wrong, it's nearly impossible to know what depended on the old value — until after the fact.

What is a Variable

Define it once. Use it everywhere.

A Variable is a named, versioned, permission-controlled value stored securely in Opal. Set the value once and reference it across every Connector, Tool, and Webhook that needs it.

  1. 01

    Key and value

    Every Variable has a key — the name used to reference it — and a value: the actual credential, token, or configuration string your integrations need.

  2. 02

    Text or secret

    Set the type based on how sensitive the value is. Text values are visible to authorized users. Secret values are protected after they are saved, so team members can use them without seeing the raw value.

  3. 03

    Reference across resources

    Reference a Variable when configuring MCP Connections, Tool Definitions, and Webhooks — no copying, no paste errors.

  4. 04

    Linked resources panel

    See everywhere a Variable is referenced, in real time. Before rotating a credential, review what depends on it so nothing breaks unexpectedly.

  5. 05

    Version tracking

    Changes to a Variable's value are recorded over time, giving teams a clear record of what changed and when.

  6. 06

    Permissions

    Control who can view, edit, or manage each Variable. Not everyone who uses an integration needs access to the credentials that power it.

Variable · anatomysecret
ANALYTICS_API_KEY
value protected after save
type · secretv4 · updatedpermissions
linked resources · 4
mcp · analyticsreferences
tool · reportingreferences
webhook · syncreferences
mcp · warehousereferences
How it works

Secure once. Stable everywhere.

Step 01

Create a Variable

Open the Variables section and define a key, add an optional description, set the type — text or secret — and enter the value.

Step 02

Reference it where needed

When configuring an MCP Connection, Tool Definition, or Webhook, reference the Variable instead of pasting the raw value.

Step 03

Share without exposing

Team members can use the Variable across configurations without ever seeing the underlying secret.

Step 04

Check before you change

Open the Linked Resources panel to see every place the Variable is referenced before rotating or updating a value.

Step 05

Update once

When a credential changes, update the Variable in one place. Every resource that references it reflects the new value immediately.

Key benefits

Credentials under control.

Centralized by design

Define a value once and reference it everywhere it is needed. Eliminate duplicates and the errors that come with them.

Secrets stay secret

Choose the secret type for sensitive values. Team members can use them in configurations without ever seeing the raw credential.

Integration-ready

Variables are built to work directly with Connectors (MCP Connections), Tools, and Webhooks — the three places integrations need credentials.

Impact visibility before every change

The Linked Resources panel shows what depends on each Variable, so teams can assess the effect of a change before they make it.

Auditability built in

Version tracking records every change, giving teams a clear, verifiable history of how credentials and configuration values have evolved.

See it in practice

Credentials managed once, used everywhere.

Rotation, shared access, and new integrations — handled from a single, governed source of truth.

Case 01
Platform Admin

API key rotation at scale

A platform administrator manages a dozen agents and integrations that connect to an external analytics service. Rather than tracking down where the API key was pasted, she defined it as a Variable from the start. When the key needs to rotate, she opens the Variable, reviews the Linked Resources panel to confirm what is affected, updates the value once, and the entire platform updates automatically.

Variable
Analytics API key
Referenced by
A dozen agents and integrations
Outcome
Rotate once, everything updates
Case 02
Security

Shared access without shared exposure

A technical lead needs three agents and two webhooks to call a payment service — but cannot share the API token in a message. He creates a Variable with the secret type, sets permissions so the relevant team members can use it without seeing the raw value, and references it in each configuration. The token is never sent in a message, pasted in a document, or emailed.

Variable
Payment service token · secret
Referenced by
3 agents · 2 webhooks
Outcome
Never pasted, never emailed
Case 03
Operations

Onboarding a new integration

A builder is setting up a new Connector to a CRM the organization just adopted. She creates a Variable for the API key, references it in the MCP Connection configuration, and adds a note in the description. When a colleague needs to set up a second connection to the same CRM six months later, the Variable already exists — same key, right description, one source of truth.

Variable
CRM API key
Referenced by
MCP Connection
Outcome
One source of truth, reused later
Security and compliance

Credentials that stay protected and traceable.

01

Role-Based Access Control

Permissions on each Variable control who can view, edit, and manage it — independent of the integrations that reference it.

02

Secret Protection

Values set to the secret type are protected after saving. Visible in use, never exposed in the interface.

03

Version History

All changes to Variable values are tracked over time, providing a clear audit trail for every credential and configuration value.

04

Zero Data Retention

ZDR is enabled automatically when models and providers that support it are used through Connectors and Tools.

05

Certifications

ISO 27001, ISO 42001, and SOC 2 Type II certifications are underway.

Variables

Manage every credential your platform needs in one place.

Store keys, tokens, and configuration values once, reference them everywhere, and rotate them without breaking a single Connector, Tool, or Webhook.