2026-08-25 23:47:20 +08:00
---
description: "Package map for the credential capability family: the credential-reference seam, the environment-and-file provider, the authorization flow registry, and how references keep secret values out of configuration."
kind: "package-group"
---
2026-08-13 15:33:29 +08:00
# credentials/ — credentials and authorization
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
English | [中文 ](README.zh.md )
2026-08-25 23:47:20 +08:00
## Summary
The `credentials/` group manages the secret values your configuration refers to by name: store an API key once, reference it from settings or `cordis.yml` , and rotate it without editing any configuration file. It provides the runtime part of the product that stores and looks up secrets (`credentials/` ), the default on-machine credential file (`credentials-local/` ), and the authorization flow registry (`authorization/` ) for credentials that cannot be configured, because getting one means asking a human. A rotated key reaches the very next model request, and a per-run environment override (`DEEPSEEK_API_KEY=… dsh` ) always wins over stored values. Secret values never enter configuration files you sync or render — only their names do, and the local file is readable by the same OS user, not by others.
## Table of Contents
- [Packages ](#packages )
- [Related documentation ](#related-documentation )
- [Dev Note ](#dev-note )
-----
< a id = "packages" > < / a >
## Packages
Three packages provide the credential feature: one stores, looks up, and removes secrets at runtime while configuration only names them; the second is the default on-machine store; the third lets plugins obtain credentials that have to be asked for. Their READMEs cover day-to-day use; the subsystem reference owns the exhaustive contracts.
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
2026-08-04 00:54:19 +08:00
| Package | Role | ctx key |
|---|---|---|
2026-08-25 23:47:20 +08:00
| [`credentials/` ](credentials/README.md ) | Store, look up, and remove secrets at runtime while configuration only names them | `ctx.credentials` |
| [`credentials-local/` ](credentials-local/README.md ) | The default on-machine store: a private YAML file, environment overrides win | registers `ctx.credentials` |
2026-08-13 15:33:29 +08:00
| [`authorization/` ](authorization/README.md ) | Plugin-owned flows that obtain a credential by asking a human | `ctx.authorization` |
docs: bilingual credentials/settings-consumer documentation, catalogs, and gates
New credentials data-structure page (type-equiv manifested), group README,
rewritten llm-deepseek/llm-pi-ai READMEs (dynamic configuration, dict
profiles, credential chain), capability-seams/service-role registration,
Agent Note (bilingual), demo compositions mounting settings-local +
credentials-local with no inline key plumbing, installSettingsSection
consumer helper on the settings seam (deduplicating both adapters' wiring),
jscpd symmetry markers for the provider twins, runtime-closure additions for
python/sdk-runtime, and doc-budget ceilings AGENTS.md 1750→1755 /
packages/README.md 850→865 for the structural one-line group rows.
2026-07-29 14:20:06 +08:00
2026-08-25 23:47:20 +08:00
-----
< a id = "related-documentation" > < / a >
## Related documentation
Start with the subsystem reference for the shared vocabulary, then the capability-seam table and the configuration surface of the local store.
- [Credentials subsystem reference ](../../docs/subsystems/credentials.md ) — `CredentialRef` and `CredentialKey` , per-operation resolution, UI-safe `CredentialInfo` , authorization flows, and the generated cordis surface.
- [Capability seams ](../../docs/capability-seams.md ) — the Service Definition / Service Provider / Consumer split this family follows.
- [Generated configuration catalog ](../../docs/config-catalog.md#deepseek-aidsh-credentials-local ) — every accepted field of the local store.
< a id = "dev-note" > < / a >
## Dev Note
< details >
< summary > Working context for maintainers — click to expand< / summary >
None.
docs: anchor each subsystem page to its package group; make group READMEs thin tables
core.md read as a type grab-bag: LLM wire vocabulary up front, the agent/loop story buried, and no correspondence to packages/core. It now opens on the packages/core control spine — the package-by-package loop map with a Page column into session/system-prompt/tools/scope — and keeps only what the spine group declares plus the repo-wide patterns: the Agent handle with its delivery/cancellation/interception contracts, the SessionEvent envelope, branded ids, the …Map pattern. The conversation vocabulary (Message/ContentBlock, the model request, adapters — 17 type-equiv blocks) moves to llm-streaming.md, which now declares packages/llm end-to-end; the duplicate ContentBlockMap paste near its seam section folds into the moved section, and the manifest, LINK_MAP, README table rows, website label (Core data structures → Core), and inbound anchors follow.
Every packages/<group>/README pair is now a thin front door in one shape: a why-first intro (bash's seam-pattern-first paragraph rewritten as 'shell execution for the agent'), the package table, and a closing pointer to the owning docs/subsystems page — the bash-style table stays the load-bearing middle. Load-bearing trailing paragraphs relocate rather than vanish: the fs no-timeout rationale becomes a filesystem.md section (both languages), session's four sectioned tables merge into one 12-row table, examples' legacy-bin H2 collapses to a pointer at jsonrpc-demo's README, and design rationale that already lives in an Agent Note or subsystem page is now linked instead of restated. All 40 pair records re-recorded.
2026-08-02 05:54:15 +08:00
2026-08-25 23:47:20 +08:00
< / details >