Skip to main content

Store credentials for workflows

Some workflow steps reach outside SKU.io: they watch a partner's FTP folder, call a supplier's API, or write to a Google Sheet. Those steps need a login. You save each login once under Workflows → Credentials, give it a name, and then pick it by name in any workflow. The secret itself is never shown again.

Before you begin​

  • Have the login details from the other system to hand: a host, username, and password for FTP or SFTP; a key or token for an API; or a Google Cloud OAuth client ID and secret for Google Sheets.
  • Credentials belong to your account, not to one workflow, so several workflows can use the same login. Once saved, a secret can be replaced but never read back.

Credential types​

TypeUse it forWhat you enter
FTPWatching, downloading from, or uploading to an FTP folderHost, Port (21 if blank), Username, Password, and the passive-mode options
SFTPThe same jobs over SFTPHost, Port (22 if blank), Username, Password
API KeyCalling an API that expects a key in a headerHeader name (for example X-API-Key) and the Key
Bearer TokenCalling an API that expects a bearer tokenToken
Basic AuthCalling an API or URL protected by a username and passwordUsername and Password
Google OAuthReading or writing Google SheetsClient ID and Client Secret, then Connect with Google
Webhook TokenKeeping a token that a receiving service gave youToken

FTP and SFTP credentials are used by the FTP / SFTP: File Available trigger and the FTP download and upload steps. API Key, Bearer Token, and Basic Auth are used by the HTTP Request and download-from-URL steps. Google OAuth is used by the Google Sheets trigger and the Google Sheets: Write Rows step.

Add a credential​

  1. Go to Workflows and click Credentials.

  2. Click New Credential.

    The New credential dialog with Name, Type set to FTP, and the FTP fields

  3. Type a Name your team will recognize, such as Acme Wholesale FTP. This is the name you pick inside a workflow.

  4. Choose the Type.

    The Type list open, showing FTP, SFTP, API Key, Bearer Token, Basic Auth, and Google OAuth

  5. Fill in the fields for that type. Secret fields are masked as you type.

    A Bearer Token credential named Supplier feed API with its token entered

  6. For Google OAuth, enter the Client ID and Client Secret, then click Connect with Google and approve access in the Google window. If you already have a refresh token, open Or enter refresh token manually (advanced) and paste it instead.

  7. Click Create credential.

The credential appears in the list with its type and a safe summary, such as the username and host for FTP, or token configured for a token. The secret is encrypted and isn't shown again.

The Workflow Credentials list with an FTP credential and a Bearer Token credential

Use a credential in a workflow​

  • From a template. When a template needs a login, its set-up page asks for it. Pick the credential by name. If the list says there are none yet, add one first, then come back.

    A template set-up page with the FTP credential list open, showing Acme Wholesale FTP

  • In the builder. Open the step that talks to the other system and choose the credential in its Credential field. The field only lists credentials of the types that step accepts.

Change or replace a secret​

  1. Click the credential's name, or its pencil icon.

    The Edit credential dialog with the type locked and the password left blank to keep the existing one

  2. Change what you need. Leave a secret field blank to keep the saved value, or type a new one to replace it.

  3. Click Save changes.

Workflows pick up the new details on their next run. You can't change a credential's Type once it exists. To switch type, add a new credential and delete the old one.

Delete a credential​

  1. Click the bin icon on the credential's row.

    The Delete Credential confirmation warning that workflows using it will fail until re-linked

  2. Click Delete.

Any workflow that uses the credential fails at that step until you pick another one. Check the workflow's run history after you delete one, see Review a workflow's run history.

Next steps​

Last verified: