Skip to main content
Some Runs need credentials to do their work — an API key passed as an environment variable, or a username and password for a website or application the agent signs into. The CLI lets you store these securely and attach them to a specific Revision of an Agent.
Values you store are encrypted at rest and never echoed back — listing a secret or login shows you which fields are set, not their values.
Secrets and logins are personal by default. Pass --shared when creating one to make it available to the whole team (requires a manager role).

Env-var secrets

A secret holds one or more environment variables that are injected into a Run at runtime.
--value takes a KEY=VALUE pair and can be repeated to store several variables under one secret. Use --service-slug <slug> to tag a secret with the service it belongs to.

Logins

A login holds a website or application credential — domain, username, password, and optional TOTP secret — that the agent uses to sign in during a Run, in the browser or in desktop sessions (Computer Use and Windows Remote Desktop).
At least one of --password or --otp-secret must be provided when creating a login. The TOTP secret lets the agent generate one-time codes for sites that require two-factor authentication.

Attaching to a Revision

Storing a secret or login doesn’t make it available to a Run on its own — you attach it to the specific Revision of an Agent whose Runs should use it.
Use duvo secrets list and duvo credentials list to find the IDs to attach, and duvo revisions list --agent <agent-id> to find Revision IDs.

Managing Agents

Find and create the Revisions you attach secrets and logins to

Managing Connections

For OAuth-based accounts (Gmail, Slack) rather than raw credentials