Secret manager credentials
Coolify supports Doppler, Infisical, and HashiCorp Vault. Add credentials under Keys & Tokens > Integration Tokens, then choose the token on a resource's Environment Variables page.
Add credentials in Coolify
- Open Keys & Tokens > Integration Tokens and select New token.
- Choose Doppler, Infisical, or HashiCorp Vault in Provider.
- Enter a Token name and the provider credentials described below.
- Select Validate and add.
To change saved credentials, select the token's edit icon and use Validate and save.
Doppler
Use either credential type:
- Service token: In Doppler, open the project and config, select Access, and create a service token. Its scope fixes the project and config.
- Service account token: Create a service account, grant it access to the required project/config, and generate a token. You select the project and config in Coolify.
Paste the token into API token in Coolify. See Doppler service tokens and service accounts.
Infisical
- Create a Machine Identity in Infisical.
- Add Universal Auth to the identity and generate a client secret.
- Grant the identity access to the project and environment containing your secrets.
- In Coolify, enter Base URL, Client ID, and Client secret.
For Infisical Cloud, use https://app.infisical.com. Self-hosted installations should use their own base URL. See Infisical Universal Auth.
HashiCorp Vault
Create a Vault policy that permits read and list on the required KV v2 secret path, then issue a token with that policy. In Coolify, enter:
- Base URL: the Vault instance URL
- Vault token: the token
- Namespace (optional): only for Vault Enterprise or HCP Vault
When linking a resource, select the KV v2 mount and secret path. Use the narrowest policy possible. See Vault tokens and policies.
Provider credentials can expose multiple secrets. Use least-privilege access, rotate credentials regularly, and do not paste them into environment variables.
