Secrets Manager

External backend active

Configure where the dashboard stores credentials and API tokens. Migrating moves secrets from the encrypted database to an external provider — no restart required.

Active Secrets Backend

Choose where new secrets are stored. Changing this setting does not move existing secrets — use Migrate Secrets below to move them.

Secrets not changed in this many days are surfaced on the dashboard's “Needs attention” panel. External-vault references use the backend's own last-rotated date; database secrets use their last-saved time. 0 disables the check.

Secret Registry

All credentials managed by the dashboard and their current location.

Loading…
Secret Backend Reference Status
No secrets configured yet.

Browse & Edit

Full CRUD on any backend. Every secret value is JSON — the editor enforces it on save.

No secrets in this backend yet.
Name Updated Actions

Name is immutable. Delete and recreate to rename.

Migrate Secrets

Move all database-stored secrets to an external backend in one step. A dry run previews what would be migrated without making changes. Secrets already on a different external backend are left untouched.

Confirm Migration

This will read every database-stored secret in plaintext, write it to , and replace the database value with a reference. This cannot be automatically undone.

Run a Dry Run first to verify which secrets will be migrated.