Skip to main content

Credentials

Credentials store the authentication details OrbisID uses to connect to target systems. All passwords are encrypted at rest using AES-256-GCM.

Viewing Credentials​

Navigate to Systems > Credentials to see all stored credentials. The table shows:

  • Name - descriptive label
  • Username - the account used to authenticate
  • Password Source - either Static (stored password) or Vault Script (retrieved dynamically from a PAM vault)
  • Private Key - whether a private key is also stored on this credential
  • Systems - number of systems using this credential

Creating a Credential​

  1. Click Add Credential
  2. Fill in the fields:
FieldRequiredDescription
NameYesA descriptive label (e.g., "AD Service Account - PROD")
UsernameYesThe username to authenticate with
Password SourceYesStatic Password or PAM Vault Script

Static Password​

Enter the password directly. It is encrypted with AES-256-GCM before being stored in the database.

Private Key​

Some connectors authenticate with a private key instead of, or alongside, a password — SSH keys for Linux, and service account PEM keys for Google Workspace and Google Cloud Platform. Paste the key into the Private Key field, not Password: Password is a masked single-line field and silently strips line breaks from anything multi-line pasted into it, while Private Key is a plain multi-line box that preserves the key's line structure. Leave Password blank for connectors that use only a private key.

If a key is pasted with escaped \n sequences instead of real line breaks — for example, copied verbatim out of a downloaded JSON service account key file, where line breaks appear as the two literal characters \n rather than an actual newline — OrbisID converts them to real line breaks automatically when the credential is saved.

PAM Vault Script​

Instead of storing a password, OrbisID can retrieve it dynamically from your PAM vault (CyberArk, BeyondTrust, Delinea, etc.) at scan time using a script that runs on the Scan Agent.

Configure:

FieldDescription
Script ModePath (script already on the agent host) or Upload (upload to OrbisID)
Script PathFor Path mode: absolute path to the script on the agent
Vault ParametersKey-value pairs passed to the script (e.g., safe, object, folder)

The script receives a JSON payload on stdin containing the vault parameters and must output the password on stdout. See On-Premise Agent - PAM Vault Scripts for the full specification.

Script Versioning​

When using Upload mode, each uploaded script is stored as a version. You can:

  • Upload new versions at any time
  • View the version history
  • Activate a specific version (the active version is used during scans)

Editing a Credential​

  1. Select a credential from the list
  2. Click Edit
  3. Modify the fields as needed
  4. Click Save
note

When editing, the password field is blank. Leave it empty to keep the existing password, or enter a new value to replace it.

Deleting a Credential​

Credentials can only be deleted if no systems are currently using them. Unassign the credential from all systems first, then delete it.

Security​

  • Passwords are encrypted using AES-256-GCM with the ENCRYPTION_KEY configured in your environment
  • Passwords are never returned in API responses
  • All credential operations are recorded in the Audit Log
  • Vault scripts avoid storing passwords in the database entirely