How it works
Credentials are stored, not copied
A credential exists once. An environment variable in a project points at it by reference rather than holding its own copy of the secret. When you rotate, every environment that references it is already correct — there is no second place to remember to update.
ALLBots / Production OPENAI_API_KEY ──▶ OpenAI Production ELEVENLABS_API_KEY ──▶ ElevenLabs Production TWILIO_AUTH_TOKEN ──▶ Twilio Production AIDentist / Production OPENAI_API_KEY ──▶ OpenAI Production ← same credential
Health is checked on a schedule
A credential that quietly stopped working is worse than one that never worked, because you find out from a customer. Verified providers are polled on a schedule that respects their rate limits, and the result is a state you can act on — not just "error".
OpenAI Production healthy checked 12m ago ElevenLabs Production healthy 83% of monthly quota used Retell Production invalid authentication rejected Stripe Live not tested no verified endpoint
Rotation is ordered so it cannot take you down
The new credential is created and validated while the old one is still live. Only after the replacement reads back correctly through the vault is the predecessor revoked. If any step fails, you still have a working key.
create ──▶ validate ──▶ store ──▶ read back ──▶ revoke old
│
any failure before this point
leaves the old key untouchedDeployment uses the platform’s own secret API
GitHub Actions secrets are encrypted with the repository public key before they leave the server. Vercel variables go in as encrypted environment values. Nothing is written into a file in your repository, and nothing appears in a build log.
ALLBots / Production ──▶ GitHub → encrypted Actions secrets
──▶ Vercel → encrypted env vars
──▶ Export → .env you paste yourself