foxora

Managing secrets and API keys

Enter credentials only in Foxora’s dedicated secret fields, restrict their scope at the provider, and rotate them immediately after suspected exposure.

Managing secrets and API keys
Studio interface in English. Sample data.
  1. Create the narrowest provider key or OAuth grant that supports the task.
  2. Add it through Settings → Models, Plugins, or Channels, depending on the integration.
  3. Confirm saved secret fields return masked rather than plaintext values.
  4. Test one harmless read before enabling write, publish, payment, or messaging actions.
  5. If exposed, revoke the credential at the provider, replace it in Foxora, and retest.

Never paste tokens into chat, source files, screenshots, logs, or support messages. Keep secret-bearing environment files out of version control. Disconnecting a Foxora integration may not revoke the provider’s credential, so complete both sides.

Expected result: the integration works with minimum scope and no full secret is visible in Foxora’s saved configuration.