Remote Credentials
Store credentials that remote sessions can use to reach external services — the token is injected into matching outbound requests and never exposed to the agent.
Remote Credentials let your Remote Workspaces reach external services — such as GitHub, package registries, or internal APIs — without exposing the access token to the agent.
You store the credential once in the Kimchi console. When a remote session makes an outbound request that matches the credential's host pattern, Kimchi injects the credential into the request automatically. The agent never sees the token value: it is added to the request as it leaves the workspace, and cannot be read back from the console either.
This means you can give a remote agent access to a private API without pasting a token into a prompt, a setup script, or a file that the agent can open.
Open the Remote Credentials page
In the Kimchi console, open the Remote Credentials page. It lives in the Remote group of the sidebar, next to Remote Sessions and Workspace Templates.
The page appears only when Remote Credentials is enabled for your organization. If you do not see it in the sidebar, contact your organization administrator.
The page lists the credentials available to you:
| Column | Shows |
|---|---|
| Name | The credential's name |
| Host pattern | Which hosts the credential is injected into |
| Injection | How the credential is attached, for example Header: Authorization or Env var: API_KEY |
| Updated | When the credential was last changed |
Credential values are never shown in the list. The page carries a reminder that credentials are visible and usable only by you.
Create a credential
Open the dialog
On the Remote Credentials page, select Add credential.
Name the credential
Enter a Name, for example GitHub token. The name helps you recognize the credential in the list.
Set the host pattern
Enter the Host pattern — the host whose outbound requests receive the credential. See Host patterns.
Choose the injection
Pick an Injection type and fill in the field it requires. See Injection types.
Paste the value
Paste the credential Value, for example the access token. The value is stored securely and cannot be read back later.
Create the credential
Select Create credential. The credential appears in the list and is injected into matching outbound requests from then on.
Injection types
Choose how the credential is attached to outbound requests:
| Injection | What to provide | Example |
|---|---|---|
| HTTP header | Header name | Authorization |
| Basic auth | Username | bot-user |
| Query param | Parameter name | api_key |
| Environment variable | Variable name | API_KEY |
The credential value is placed into the request according to the selected type:
- HTTP header — added as the value of the header you name.
- Basic auth — used as the password for the username you provide.
- Query param — appended to the request URL under the parameter name you provide.
- Environment variable — made available to the remote session under the variable name you provide.
Host patterns
The host pattern decides which requests receive the credential:
- An exact lowercase hostname — for example
api.github.com. Only requests to that host are affected. - A wildcard — for example
*.example.com. Requests to the domain and all its subdomains are affected.
A host pattern is a hostname only. Ports, paths, and URL schemes are not supported, and the pattern must be lowercase.
Credential values and security
- Values are stored securely and never shown in the console — after you create a credential, its value cannot be read back.
- The agent running in a remote session never receives the token value. Credentials are injected into outbound requests as they leave the workspace.
- Give each credential a descriptive name so you can recognize it, and use the narrowest host pattern that covers the hosts the credential is meant for.
Edit a credential
Select Edit from the credential's ⋯ menu. Change the name, host pattern, or injection settings, then select Save changes.
To rotate a value, enter a new one in the Value field — leave it empty to keep the current value unchanged. Rotated values take effect on subsequent outbound requests.
Delete a credential
Select Delete from the credential's ⋯ menu and confirm in the dialog. The value is removed immediately: outbound requests to the credential's host pattern no longer receive it.
See also
- Remote Workspaces — Workspaces and sessions,
/teleport, and Remote Execution. - Workspace Templates — Reusable workspace configurations, including setup scripts.
- User Roles — Manage roles and permissions in your organization.
Updated about 3 hours ago