# Secrets

Secrets store sensitive credentials for Tailglow features that need them. Each secret belongs to
you within the selected team, so teammates cannot view or use it.

## Add an AI provider key

1. Open **Team Settings**.
2. Select **Agents**.
3. Choose **OpenAI** or **Anthropic** and add your API key.
4. Save the key.

After saving, Tailglow hides the full value and shows only its last four characters for
identification.

## Manage secrets

From **Team Settings** > **Agents**, you can view a key's label, provider, and last four characters,
change its label, or delete it.

Chat uses your saved key when you select that provider's model. Selecting **Tailglow** uses
managed access and the team's credits even when your own key is connected. Deleting a key does
not silently switch billing to Tailglow; choose another available model to continue.

## Keep secrets safe

Secret values are encrypted before storage and are never returned after creation. If a credential
may have been exposed, delete the secret, rotate the credential with its provider, and add the new
value.
