> ## Documentation Index
> Fetch the complete documentation index at: https://docs.checkfu.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Vaults and Credentials

> Keep secret custody separate from account access and permission.

A **Vault** owns secret-bearing Credential custody. A **Connection** is the
governed, nonsecret link to an external account or provider capability.
Selecting either resource does not grant permission.

## Keep credentials at the trusted boundary

Custodied Credential values resolve only at the trusted effect boundary.
Checkfu does not return or inject them into Agent instructions, model context,
harness configuration, Session events, sandbox files, or Tool payloads.
Keep your own secrets out of prompts, Files, Memory, Tool arguments, and results.

[Connection custody details](/concepts/capabilities#connections-and-credential-custody)
explain revocation and the trusted action path. The
[Session credential-vault guide](/guides/session-credential-vaults) covers
selecting Vault references for a Session.

## Distinguish custody from ConnectionVault grouping

A **ConnectionVault** is a named grouping of Connections and member access.
It compiles membership into ordinary PermissionAssignments. The grouping
itself is never a second permission system, and archiving it does not revoke
the assignments it compiled.

See [ConnectionVault behavior](/concepts/capabilities#vaults-a-named-grouping-not-a-second-permission-system)
for apply, conflicts, group membership, and revocation.
[Permissions and governance](/concepts/tenancy-and-governance) remain the
source of truth for live access.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.