Staging sandbox
Global Clinic ConnectGuides
← All screen guides
ConfigurationAvailable

Security and credentials

A metadata-only health view for credentials owned by the active clinic. Secret values never appear here. Open the owning WhatsApp, social, webhook, website, or developer screen to create, replace, rotate, restore, or remove a credential.

01

What you can do here

Encrypted tenant credential vault

Recoverable integration credentials are encrypted independently and linked to the exact tenant-owned connection that uses them. The overview shows lifecycle health and dates without exposing values, vault references, or secret-derived hints.

Clear lifecycle states

Configured, staged, overlap, pending deletion, and expired states show where follow-up is required. A staged credential does not become active until its owning workflow completes the required provider check or signed test.

Hash-only developer keys

Developer API keys remain one-way hashes. Their plaintext is shown only when a key is created and can never be revealed or recovered from this page.

02

Follow these steps

Review credential health

  1. Confirm the active clinic in the workspace switcher.
  2. Review any group marked as needing attention.
  3. Select Manage on the affected row to open the owning workflow.
  4. Use separate Replace, Prepare rotation, Activate, Restore, or Remove actions as directed on that screen.
03

Helpful habits

  • Use generated signing values when the receiving system supports them, and copy them only into the intended server-side or provider configuration.
  • Test staged webhook and signing-key replacements before activation so production traffic continues using the current value during setup.
  • Treat a pending deletion as disabled immediately. Restore it only when the integration is still authorized for the active clinic.
04

Tips

  • Tenant owners and administrators can see this metadata, but sensitive actions also require a recent Clerk verification.
  • WhatsApp access tokens, PINs, OAuth tokens, account passwords, and provider client secrets are permanently write-only after submission.
Next