Steroid Kit logo

Steroid_Kit

Steroid Vault›Managing Secrets

Managing Secrets

This guide covers the full lifecycle of a secret in the Steroid Vault: opening the Vault, adding credentials for each MCP server, editing or rotating them, and understanding the server-specific naming conventions.

Open Vault

Open the Vault TUI

steroid
# Navigate to VAULT, then press Enter

The first screen lists servers already present in the credential index, not every catalog server. Open a server with Enter to manage SECRETS/CONFIG. There are no last-used-30-days columns.

Managing secrets — open vault
KeyAction
EnterOpen the selected server
TabSwitch SECRETS/CONFIG tables
AAdd an entry to the active table
EEdit the selected secret's value
DDelete the selected secret (prompts for confirmation)

Add a Secret

  1. First-use tool/build elicitation creates a new server entry; the Vault list is not a free-form catalog browser.
  2. Open an indexed server, select SECRETS, and press A.
  3. Enter the exact catalog secret name, including its prefix (see the table).
  4. Enter the masked value and confirm. Persistent storage uses the encrypted-file keyring; check any persistence warning.
  5. For CONFIG, use the exact flat path such as slack.team_id; config and secrets are distinct.
  6. Index changes invalidate the local cache. Refresh cloud AP Connections separately when rotating credentials used by published flows.
Managing secrets — add a secret

Secret names are case-sensitive and must match the convention Steroid expects. Using the wrong name means Steroid can't find the secret, and the tool call will fail with a vault miss.

ServerSecret NameNotes
github-officialgithub.personal_access_tokenGrant permissions appropriate to the repository and operation
slackslack.bot_tokenServer config also requires slack.team_id
notionnotion.internal_integration_tokenAllow the integration access to required pages
bravebrave.api_keyBrave Search API credential
postgrespostgres.urlSecret connection URL, not a separate password/config.connection_string

Edit / Delete

Edit a Secret

  1. Use arrow keys to highlight the secret you want to change.
  2. Press E to open the edit dialog.
  3. The current value is pre-filled in a masked input; replace it with the intended value.
  4. Press Enter to save. The vault entry is updated in place.
  5. Local index changes invalidate cached credentials; persisted cloud AP Connections have a separate refresh lifecycle.

Delete a Secret

  1. Highlight the secret using arrow keys.
  2. Press D. A confirmation prompt appears showing the secret name.
  3. Use the confirmation dialog button to confirm deletion.
  4. Later local calls can elicit the missing value again. Deletion is not third-party token revocation and does not remove a cloud AP Connection.

NOTE

steroid cred store opens the local credential TUI directly. Adding OpenAI or Anthropic keys here does not enable Invoke LLM models; those are advertised by authenticated coding-agent CLIs.

On this page