Skip to content
aheldocs

Type to search every page. Use the arrow keys to move and Enter to open.

    Use apps · How-to guide

    Give an app a key with the vault

    Paste, replace or remove an app's API key or sign-in in the ahel vault. Keys are sealed on arrival and never shown to your AI.

    Use this when an app asks for an API key, or when you need to replace or remove a key or a sign-in. Keys and sign-ins live in your workspace's vault. ahel adds them on the server when a call runs, so your AI never sees them and they never appear in a chat.

    Only workspace owners and team leads can manage the vault. Other members see "Owners and team leads manage the vault."

    Add a key

    1. Create a key in the app vendor's own settings. Give it only the permissions you want your AI to have.
    2. In your workspace, open Apps and choose the app, or press Connect on the app in Discover.
    3. The panel shows "1. Get the key in" the vendor and "2. Paste it here". Paste the key and press Save.

    The panel then says the app is connected and how many actions your AI can use, with a link to try it in your AI. The key "is sealed on arrival and never shown again". Afterwards ahel shows only a short masked preview, so you can tell which key is stored.

    Sign in instead of a key

    For an app that connects by signing in, press Sign in with the app's name. The vendor's own sign-in screen opens; approve access and you are back in ahel. The account row shows Signed in. When a sign-in expires, the row shows Sign-in needed and a Sign in again button.

    Add a second account

    To use two accounts with the same app, such as a work and a test account, open the app and choose Connect another account (for a sign-in app) or Add account (for a key app).

    Replace a key

    1. Open the app on your Apps page and choose Edit account.
    2. Paste the new key. Fields you leave empty keep their saved values.
    3. Press Save changes.

    Do this when you rotate a key at the vendor, or when the old key lacked a permission an action needs.

    Remove a key or a sign-in

    Open the app's account, press Remove, then Confirm removal. The sealed value is deleted, and your AI can no longer use that account. Revoke the key in the vendor's settings as well if you no longer need it.

    See when a key was used

    Every use of a key is recorded. Open Activity: key uses are tagged Key, beside every call your AI made. Each account row on the Apps page also links to its run history.

    How the vault protects a key

    • A key is encrypted before it is stored, and ahel uses it only on the server, to make the call your AI asked for.
    • No screen and no API reads a key back out. To change one, you replace it.
    • Your AI's tool settings hold only the connector address, never an app key.

    For the full picture, see Security.

    Last updated 5 October 2026