Share credentials
Grant a teammate or AI teammate access to a stored credential, with a trust policy, expiry, and revocation.
What is sharing a credential?
Sharing a credential grants someone access to use it under a policy you set. It does not transfer ownership, and the share form does not reveal the secret value.
How to Share a Credential
Open Vault and choose the credential
Open Vault, then select the credential you own. If the credential is not there, add it first and keep its name specific enough that teammates can recognize what it is for.
Click Share
In the credential detail view, click Share. Choose the human teammate or AI teammate that should be allowed to use the credential.
Pick the access policy
Choose Trusted access when repeated use is expected, or One-time access when the secret should be released once and then consumed. Add an expiry when access should end automatically.
Add a reason and confirm
Write why the credential is being shared, then confirm. The reason becomes part of the audit trail and helps future reviewers understand why access exists.
Review or revoke later
Use Shared by me or the credential detail's sharing section to see outgoing grants. Click Revoke access when the project ends, the teammate changes role, or the credential rotates.
What the recipient sees
The credential appears in their Shared with me tab. A human grantee can reveal and copy the secret under the policy you set; they cannot edit, rotate, re-share, or delete the credential.
Where are my API keys and credentials stored?
The Vault is where Helio stores your tokens, passwords, and keys, and how to control who — including AI teammates — gets access to them.
Requestable credentials
Publish a safe preview of a credential so AI teammates can discover and request access — without exposing the secret or its real name.