How it works

Credentials are stored, not copied

A credential exists once. An environment variable in a project points at it by reference rather than holding its own copy of the secret. When you rotate, every environment that references it is already correct — there is no second place to remember to update.

ALLBots / Production
  OPENAI_API_KEY      ──▶  OpenAI Production
  ELEVENLABS_API_KEY  ──▶  ElevenLabs Production
  TWILIO_AUTH_TOKEN   ──▶  Twilio Production

AIDentist / Production
  OPENAI_API_KEY      ──▶  OpenAI Production   ← same credential

Health is checked on a schedule

A credential that quietly stopped working is worse than one that never worked, because you find out from a customer. Verified providers are polled on a schedule that respects their rate limits, and the result is a state you can act on — not just "error".

OpenAI Production        healthy       checked 12m ago
ElevenLabs Production    healthy       83% of monthly quota used
Retell Production        invalid       authentication rejected
Stripe Live              not tested    no verified endpoint

Rotation is ordered so it cannot take you down

The new credential is created and validated while the old one is still live. Only after the replacement reads back correctly through the vault is the predecessor revoked. If any step fails, you still have a working key.

create ──▶ validate ──▶ store ──▶ read back ──▶ revoke old
                                            │
                        any failure before this point
                        leaves the old key untouched

Deployment uses the platform’s own secret API

GitHub Actions secrets are encrypted with the repository public key before they leave the server. Vercel variables go in as encrypted environment values. Nothing is written into a file in your repository, and nothing appears in a build log.

ALLBots / Production ──▶ GitHub  →  encrypted Actions secrets
                     ──▶ Vercel  →  encrypted env vars
                     ──▶ Export  →  .env you paste yourself