Secrets: Storage
Catalog id: resource.secrets.storage
Which backend currently holds secrets for the scope you are in. A tenant has exactly one active assignment, and everything that creates a secret handle or resolves a stored credential goes through it. The platform has its own storage for bootstrap secrets and platform-operated integrations.
The screen is deliberately thin. Choosing a different backend is a migration rather than an edit, and that lives on Provider and Migrations.
Audience: tenant administrator for the tenant scope, platform operator for the platform scope.
Guide: Secrets and KMS providers.
Reading the current assignment
The tenant's assignment
GET/api/platform/config/v1/tenants/00000000-0000-4000-8000-000000000000/secrets/assignment200 OK- Admin Console
- Request
- Response
- Try it
The assignment carries a display name, the provider type, the lifecycle state, and source, which
says whether the backend came from a platform offering or is one the tenant runs itself. The captured
tenant uses a platform offering.
source decides who rotates the credential behind it. A platform offering rotates on the platform
side and the tenant does nothing; a tenant-managed provider rotates from the tenant's own Provider
tab.
version is what a conditional write needs, so read before you write. Mutations use If-Match with
a strong ETag, and two operators editing the same assignment get a conflict rather than one silently
overwriting the other.
An assignment that is missing or unhealthy does not stop forms from opening. Email accounts and connectors still save and still validate, then fail when they actually need a secret. That is why this is the first screen to check when something that stores a credential misbehaves.

- Admin Console
- Request
- Response
- Try it
Switch the tenant picker to platform and the same area shows the platform's assignment. The captured
deployment uses environment storage with readOnly: true, which is the normal shape for a packaged
deploy: values arrive from deployment configuration, so the console disables credential priming and
writes rather than offering edits that would not take effect.
Change storage exists for a deliberate move of platform secrets into Vault or a cloud secret manager. Whatever you pick should stay under platform control; pointing platform storage at a customer-controlled vault mixes two trust boundaries that need to stay apart.

Full schema: Secret Management API.