> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cloud.cdata.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Keys

> Store data source authentication information in key vaults.

Connect AI supports storing data source authentication information in key vaults. Instead of entering authentication information directly in the **Add Connection** page for your data source, you enter the name of the key vault. You can then update the information in the key vault without affecting your data connection.

<Note>
  * Currently supports Azure Key Vault. Support for additional key vault providers is planned.
  * Available for Business tier in Connect AI only.
  * Not available for Connect AI Embed.
</Note>

## Azure Key Vault Prerequisites

Before configuring Connect AI, complete the following steps in the Azure Portal.

### Create an Azure Key Vault

<Steps>
  <Step>
    In the [Azure Portal](https://portal.azure.com), search for **Key vaults** and click **Create**.
  </Step>

  <Step>
    Select your **Subscription**, **Resource group**, **Key vault name**, and **Region**.
  </Step>

  <Step>
    Click **Review + create**.
  </Step>

  <Step>
    After the vault is created, open it and note the **Vault URI** from the **Overview** page. It follows the pattern `https://<vault-name>.vault.azure.net/`.

    <Frame>
      <img src="https://mintcdn.com/cdata/SGQi_ErUoo357Nb5/en/images/settings_keyvault_URI.png?fit=max&auto=format&n=SGQi_ErUoo357Nb5&q=85&s=e516cd6e39be01db2bf5a12840167343" alt="Key Vault URI" width="739" height="395" data-path="en/images/settings_keyvault_URI.png" />
    </Frame>
  </Step>
</Steps>

### Register an Application in Microsoft Entra ID

Connect AI authenticates to your key vault using a registered application (service principal).

<Steps>
  <Step>
    In the Azure Portal, navigate to **Microsoft Entra ID** > **Manage** > **App registrations** > **New registration**.
  </Step>

  <Step>
    Enter a **Name** for the application and click **Register**.
  </Step>

  <Step>
    On the app's **Overview** page, note the **Application (client) ID** and the **Directory (tenant) ID**.

    <Frame>
      <img src="https://mintcdn.com/cdata/SGQi_ErUoo357Nb5/en/images/settings_keyvault_appid.png?fit=max&auto=format&n=SGQi_ErUoo357Nb5&q=85&s=522aa6b1de36509d769c2a688a8b8b99" alt="Application and Directory ID" width="738" height="407" data-path="en/images/settings_keyvault_appid.png" />
    </Frame>
  </Step>

  <Step>
    Go to **Manage** > **Certificates & secrets** > **New client secret**. Enter a description, select an expiration, and click **Add**.
  </Step>

  <Step>
    Copy the secret **Value** immediately. It is not shown again after you leave the page.

    <Frame>
      <img src="https://mintcdn.com/cdata/SGQi_ErUoo357Nb5/en/images/settings_keyvault_secret.png?fit=max&auto=format&n=SGQi_ErUoo357Nb5&q=85&s=ae9fc1797a7c6e1168cfedf4349b8cb3" alt="Certificates and secrets" width="736" height="376" data-path="en/images/settings_keyvault_secret.png" />
    </Frame>
  </Step>
</Steps>

### Grant the Application Access to the Key Vault

<Steps>
  <Step>
    Open your key vault in the Azure Portal and go to **Access policies** > **Create**.

    <Frame>
      <img src="https://mintcdn.com/cdata/SGQi_ErUoo357Nb5/en/images/settings_keyvault_access.png?fit=max&auto=format&n=SGQi_ErUoo357Nb5&q=85&s=f7117a1355281e0cb266aa07a05b8540" alt="Access policies" width="737" height="455" data-path="en/images/settings_keyvault_access.png" />
    </Frame>
  </Step>

  <Step>
    Under **Secret permissions**, select **Get** and **List**.
  </Step>

  <Step>
    Under **Principal**, search for and select the application you registered, then click **Next**.
  </Step>

  <Step>
    Click **Next** through the **Application** tab (no changes required).
  </Step>

  <Step>
    Review the policy and click **Create**. This allows Connect AI to read secrets from the vault.
  </Step>

  <Step>
    Back on the **Access policies** page, verify that your access policy is listed.
  </Step>
</Steps>

## Create a New Key Vault

<Steps>
  <Step>
    Click **+ Add Vault**. The **Add Azure Key Vault** dialog appears.

    <Frame>
      <img src="https://mintcdn.com/cdata/-CG7rbvPUnfqNHru/en/images/settings_add_vault.png?fit=max&auto=format&n=-CG7rbvPUnfqNHru&q=85&s=b0a823277c2452fe6c866821035434c9" alt="Add Azure key vault" width="601" height="692" data-path="en/images/settings_add_vault.png" />
    </Frame>
  </Step>

  <Step>
    Enter a **Vault Name** to identify this vault in Connect AI. This does not have to match the Azure vault name.
  </Step>

  <Step>
    Enter the **Vault URI**. This is the URI from the **Overview** page of your key vault in the Azure Portal (for example, *[https://my-vault.vault.azure.net/](https://my-vault.vault.azure.net/)*). This is in the Create an Azure Key Vault step of the prerequisites.
  </Step>

  <Step>
    Enter the **Application Id**, also known as the **Client Id**. This is the **Application (client) ID** from the **Overview** page of your app registration in Microsoft Entra ID (In the Register an Application in Microsoft Entra ID step in the prerequisites).
  </Step>

  <Step>
    Paste the **Client Secret** value you copied when you registered the application in Microsoft Entra ID (in the Register an Application in Microsoft Entra ID step in the prerequisites).
  </Step>

  <Step>
    Enter the **Directory Id**, also known as the **Tenant Id**. This is the **Directory (tenant) ID** from the **Overview** page of your app registration in Microsoft Entra ID (in the Register an Application in Microsoft Entra ID step in the prerequisites)
  </Step>

  <Step>
    Click **Confirm** to save your credentials. If successfully saved, the new key vault appears in the list of key vaults, along with the **Key Vault URL** and **Creation Date**.
  </Step>
</Steps>

Once you create a new key vault, you can use the key vault as a credential for data source connections.

## Delete a Key Vault

To delete a key vault that you no longer use, click the delete icon in the key vault list.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.