Configure
Credentials
Keep model keys in the Tenant and attach MCP credentials to a session.
Model credentials live in the Tenant vault. They never reach your app, the
agent loop, or the sandbox. Set them with npx @nylorun/cli configure, Studio
Model Settings, or the .env seed on first nylorun start. See
Models.
MCP credentials
Outbound MCP servers that need a URL-bound token take that credential from a vault attached to the session:
await client.createSession({
agentId: "assistant",
ownerUserId: authenticatedUser.id,
vaultIds: [vaultId],
});Attach only vaults that belong to the same ownerUserId as the session. Reads
return metadata, never the secret. The Tenant model credential is not
attachable to a session.
Open source does not sign people in or store their secrets for you. Your app owns identity; plug your own secret store into the session you open.