Esc

Start typing to search.

Improvado
Sign In

Custom Pipeline Secrets

Written by Ilya Sudakov

Updated on Sep 28, 2026

Overview

Most pipelines reach your data through the connections already in your workspace. When a pipeline needs a service that has no Improvado connection — a public API with its own key, an internal endpoint, an SFTP password — you store that credential as a secret. The pipeline reads it by name when it runs; the value never appears in the pipeline code, in chat or in run logs.

Pipeline secrets and workspace secrets

Secret Who can read it Where you manage it
Pipeline secret Runs of that one pipeline The pipeline's Secrets tab
Workspace secret Every pipeline in the workspace Custom Pipelines → Workspace secrets

Use a workspace secret for a key several pipelines share, and a pipeline secret for everything else. If a pipeline has its own secret with the same name as a workspace secret, the pipeline's value wins for that pipeline.

Adding a secret

Ask the AI Agent to build or change the pipeline and say which service it needs a key for. The Agent writes the pipeline to read the secret by name — for example SLACK_WEBHOOK_URL. It will not ask you to paste the value into chat.

Open the pipeline and go to the Secrets tab. A secret the code needs but that has no value yet is listed as Required by code, no value set.

Secrets tab: two secrets required by code with no value set, and a workspace secret

Click Set value on that row — or New secret and enter the name exactly as listed — then paste the value.

Under Available to, choose This pipeline only or Every pipeline of the workspace, then click Add secret.

New secret dialog with the name filled in, Available to set to This pipeline only, and an empty value

Run the pipeline to check that it can reach the service.

Values are write-only

Once saved, a value is never shown again — not in the UI, not to the Agent. To change it, use Update secret and paste the new value.

Changing or removing a secret

Update or delete a pipeline secret on the pipeline's Secrets tab, and a workspace secret on the Workspace secrets page. A changed or deleted secret reaches pipelines within about 5 minutes, including runs that are already going — so rotating a key does not require editing or restarting the pipeline.

Secret names use capital letters, digits and underscores and start with a letter, for example HUBSPOT_PRIVATE_APP_TOKEN.

Troubleshooting

Symptom Usual cause
Run fails because a secret is missing The Secrets tab lists it as Required by code, no value set — add the value, then rerun
Run fails with an authorization error from the service The key expired or was revoked on the service's side — update the secret; the next run uses the new value
You can't see New secret Your role doesn't include managing pipeline secrets — ask a workspace admin

Was this article helpful?