Remote Credentials

Store credentials that remote sessions can use to reach external services — the token is injected into matching outbound requests and never exposed to the agent.

Remote Credentials let your Remote Workspaces reach external services — such as GitHub, package registries, or internal APIs — without exposing the access token to the agent.

You store the credential once in the Kimchi console. When a remote session makes an outbound request that matches the credential's host pattern, Kimchi injects the credential into the request automatically. The agent never sees the token value: it is added to the request as it leaves the workspace, and cannot be read back from the console either.

This means you can give a remote agent access to a private API without pasting a token into a prompt, a setup script, or a file that the agent can open.

Open the Remote Credentials page

In the Kimchi console, open the Remote Credentials page. It lives in the Remote group of the sidebar, next to Remote Sessions and Workspace Templates.

📘

The page appears only when Remote Credentials is enabled for your organization. If you do not see it in the sidebar, contact your organization administrator.

The page lists the credentials available to you:

ColumnShows
NameThe credential's name
Host patternWhich hosts the credential is injected into
InjectionHow the credential is attached, for example Header: Authorization or Env var: API_KEY
UpdatedWhen the credential was last changed

Credential values are never shown in the list. The page carries a reminder that credentials are visible and usable only by you.

Create a credential

Open the dialog

On the Remote Credentials page, select Add credential.

Name the credential

Enter a Name, for example GitHub token. The name helps you recognize the credential in the list.

Set the host pattern

Enter the Host pattern — the host whose outbound requests receive the credential. See Host patterns.

Choose the injection

Pick an Injection type and fill in the field it requires. See Injection types.

Paste the value

Paste the credential Value, for example the access token. The value is stored securely and cannot be read back later.

Create the credential

Select Create credential. The credential appears in the list and is injected into matching outbound requests from then on.

Injection types

Choose how the credential is attached to outbound requests:

InjectionWhat to provideExample
HTTP headerHeader nameAuthorization
Basic authUsernamebot-user
Query paramParameter nameapi_key
Environment variableVariable nameAPI_KEY

The credential value is placed into the request according to the selected type:

  • HTTP header — added as the value of the header you name.
  • Basic auth — used as the password for the username you provide.
  • Query param — appended to the request URL under the parameter name you provide.
  • Environment variable — made available to the remote session under the variable name you provide.

Host patterns

The host pattern decides which requests receive the credential:

  • An exact lowercase hostname — for example api.github.com. Only requests to that host are affected.
  • A wildcard — for example *.example.com. Requests to the domain and all its subdomains are affected.

A host pattern is a hostname only. Ports, paths, and URL schemes are not supported, and the pattern must be lowercase.

Credential values and security

  • Values are stored securely and never shown in the console — after you create a credential, its value cannot be read back.
  • The agent running in a remote session never receives the token value. Credentials are injected into outbound requests as they leave the workspace.
  • Give each credential a descriptive name so you can recognize it, and use the narrowest host pattern that covers the hosts the credential is meant for.

Edit a credential

Select Edit from the credential's ⋯ menu. Change the name, host pattern, or injection settings, then select Save changes.

To rotate a value, enter a new one in the Value field — leave it empty to keep the current value unchanged. Rotated values take effect on subsequent outbound requests.

Delete a credential

Select Delete from the credential's ⋯ menu and confirm in the dialog. The value is removed immediately: outbound requests to the credential's host pattern no longer receive it.

See also

  • Remote Workspaces — Workspaces and sessions, /teleport, and Remote Execution.
  • Workspace Templates — Reusable workspace configurations, including setup scripts.
  • User Roles — Manage roles and permissions in your organization.

Did this page help you?