Secret manager credentials

Coolify supports Doppler, Infisical, and HashiCorp Vault. Add credentials under Keys & Tokens > Integration Tokens, then choose the token on a resource's Environment Variables page.

Add credentials in Coolify

  1. Open Keys & Tokens > Integration Tokens and select New token.
  2. Choose Doppler, Infisical, or HashiCorp Vault in Provider.
  3. Enter a Token name and the provider credentials described below.
  4. Select Validate and add.

To change saved credentials, select the token's edit icon and use Validate and save.

Doppler

Use either credential type:

  • Service token: In Doppler, open the project and config, select Access, and create a service token. Its scope fixes the project and config.
  • Service account token: Create a service account, grant it access to the required project/config, and generate a token. You select the project and config in Coolify.

Paste the token into API token in Coolify. See Doppler service tokens and service accounts.

Infisical

  1. Create a Machine Identity in Infisical.
  2. Add Universal Auth to the identity and generate a client secret.
  3. Grant the identity access to the project and environment containing your secrets.
  4. In Coolify, enter Base URL, Client ID, and Client secret.

For Infisical Cloud, use https://app.infisical.com. Self-hosted installations should use their own base URL. See Infisical Universal Auth.

HashiCorp Vault

Create a Vault policy that permits read and list on the required KV v2 secret path, then issue a token with that policy. In Coolify, enter:

  • Base URL: the Vault instance URL
  • Vault token: the token
  • Namespace (optional): only for Vault Enterprise or HCP Vault

When linking a resource, select the KV v2 mount and secret path. Use the narrowest policy possible. See Vault tokens and policies.

Protect provider credentials

Provider credentials can expose multiple secrets. Use least-privilege access, rotate credentials regularly, and do not paste them into environment variables.

Next, use the secret manager with a resource.

On this page