Connectors
Mount brokered credentials for ClickHouse, OpenAI, Anthropic, GitHub, or Slack into a dev box without writing the real value to its disk.
Connect a service
In the dashboard's Connectors, choose a provider and a box, then paste the credential. It becomes an encrypted workspace secret, which a contractor's role does not include: the box sees a placeholder under the env name below, swapped for the real value on HTTPS requests to the allowed host (plain HTTP is refused).
| Connector | Default env name | Allowed host |
|---|---|---|
| ClickHouse | CLICKHOUSE_PASSWORD | The HTTPS endpoint you enter |
| OpenAI | OPENAI_API_KEY | api.openai.com |
| Anthropic | ANTHROPIC_API_KEY | api.anthropic.com |
| GitHub | GITHUB_TOKEN | api.github.com, github.com |
| Slack | SLACK_BOT_TOKEN | slack.com |
ClickHouse
Enter the HTTPS endpoint (for example https://abc.clickhouse.cloud:8443) and the password. Only the password is mounted, on the box you picked alone (widen it under Dashboard → Secrets); the endpoint, username, and database belong in your project's non-secret config.
curl -sS "$CLICKHOUSE_URL/?database=$CLICKHOUSE_DATABASE" -H "X-ClickHouse-User: $CLICKHOUSE_USER" -H "X-ClickHouse-Key: $CLICKHOUSE_PASSWORD" --data-binary 'SELECT 1'Client compatibility
The client must send the env value unchanged in an HTTPS request header, as most bearer-token SDKs do. A client that transforms it first (into Basic-auth base64, say) gets no substitution: send a raw token header, or store the transformed value as the credential if the upstream accepts it.
Rotate or remove
Rotate or delete the credential under Secrets; the box's Settings tab, under Secrets, shows and removes its env binding.