NylorunDocsBeta
RunConfigure

Credentials

Keep model keys in the Tenant and attach MCP credentials to a session.

Model credentials live in the Tenant vault. They never reach your app, the agent loop, or the sandbox. Set them with npx @nylorun/cli configure, Studio Model Settings, or the .env seed on first nylorun start. See Models.

MCP credentials

Outbound MCP servers that need a URL-bound token take that credential from a vault attached to the session:

await client.createSession({
  agentId: "assistant",
  ownerUserId: authenticatedUser.id,
  vaultIds: [vaultId],
});

Attach only vaults that belong to the same ownerUserId as the session. Reads return metadata, never the secret. The Tenant model credential is not attachable to a session.

Open source does not sign people in or store their secrets for you. Your app owns identity; plug your own secret store into the session you open.

Next step

On this page