
How connectors sign in
The agent never asks for a key in the chat. If you paste one into a message anyway, Vibely removes it before sending (“Removed a … from your message”) and offers Open Secrets so you can store it properly.
Where credentials live
Who can use a connection follows from where it’s stored, and the Who can use this connection box on the new-connection screen says which applies:
- Chat connectors are personal. Only you use them, in your chats and builds.
- App connectors saved to a project can be used by everyone who can build in that project, and by the published app.
- App connectors saved to the workspace can be used in every project in the workspace, and by those projects’ published apps.
VIBELY_ or SUPABASE_ are reserved. Vibely sets them automatically, and you can’t create or override them.
Public values are the exception
Some values are meant to be public and ship in your app: a Stripe publishable key, RevenueCat’s per-store SDK keys, an analytics project key. These use theVITE_ prefix on web and EXPO_PUBLIC_ on mobile, and they live in the project’s checked-in .env.
What the agent can and can’t see
The agent reads and writes your project files, but it can’t read connector credentials:- When the agent asks for a key, you type it into a secure dialog. The agent only learns which names were saved.
- When your app calls an OAuth connector, the request goes through the gateway, which attaches the token on the server.
- The agent references secrets by name in code, for example
Deno.env.get("RESEND_API_KEY"). It never writes the value into a file.

Per-user connections
A normal app connection uses one shared account, so every visitor of your app acts through it. A per-user connection lets each person who signs in to your published app connect their own account, and your app acts on their behalf with their own permissions.Available providers
Per-user connections work with GitHub, Notion, and Linear. They need your app to have sign-in through Supabase auth, because each connection is tied to a signed-in user. Stripe and API-key connectors don’t support them.Set one up
Ask for it in your project chat, for example:Rotate or revoke a credential
- OAuth connections: open the connector in Customize → Connectors and click Disconnect, then connect again. You can also revoke Vibely’s access in the tool’s own settings.
- Keys: add the secret again with the new value in your project’s Secrets, or ask the agent to update it. The new value replaces the old one.
- Custom MCP servers: remove the server and add it again with new credentials.
If a secret leaks
- Rotate the key at the source first: the provider’s dashboard, such as Stripe or RevenueCat.
- Save the new value in Vibely.
- Ask the agent to check the project for other exposed keys, or run a scan from the Security view.