Manage Integration Credentials
See, test, rotate, rename, and delete the third-party secrets that Mondoo integrations use to connect to other services.
A credential is a third-party secret, such as an access key, token, or client secret, that Mondoo stores once so integrations can use it to connect to another service. Instead of each integration holding its own copy of a secret, the integration references the credential. When the secret changes, you rotate the credential in one place.
These credentials are secrets Mondoo uses to reach other services. To give your own services, scripts, and pipelines access to Mondoo, use service accounts, API tokens, or workload identity federation.
Which integrations create credentials
When you add one of these integrations, Mondoo stores the secret you enter as a credential in the same space or organization:
- Slack
- GitHub (token-based setup)
- AWS, hosted (static access key mode)
- GCP, hosted (service account key mode)
- Azure (except when it uses workload identity federation)
- Microsoft 365 (except when it uses workload identity federation)
- Microsoft Defender
- Microsoft Intune
- SecurityScorecard
Other integrations store their secret on the integration itself. A credential belongs to exactly one space or organization, and only integrations in that same space or organization can use it.
View credentials
-
Navigate to the space or organization.
-
In the left navigation, select Settings, then Credentials.
The list shows each credential's:
| Column | What it shows |
|---|---|
| Name | The credential's display name. |
| Identifier | A non-secret value that identifies the secret, such as a key ID or client ID, where one exists. |
| Kind | The type of secret, such as an AWS access key or a GitHub personal access token. |
| Used by | How many integrations use the credential, or Not in use. |
| Expires | When the secret expires, if it has an expiry date. |
| Last checked | When Mondoo last tested the credential, or Never. |
| Status | The result of the last check: Healthy, Invalid, Expired, Check failed, or Not checked. |
Select a credential's name to open its detail page, which also lists the integrations that use it and lets you copy its MRN.
To see credentials, you need the Editor or Admin role, or the Integrations Manager permission.
Test, rotate, rename, or delete a credential
Open the menu in a credential's Status column, or use the buttons on its detail page:
- Test: Check the stored secret against the service now and update Status and Last checked.
- Rotate: Enter a replacement secret. Every integration that uses the credential switches to the new secret as soon as you rotate. Use this when you renew a key or token, instead of editing each integration.
- Rename: Change the display name. The stored secret and its health don't change.
- Delete: Permanently delete the credential and its stored secret. You can't delete a credential that integrations still use; Mondoo lists them so you can point them at another credential or remove them first.