Static API keys use the same connection access API as OAuth credentials. Add a
trusted provider named secret to your deployment:
Store and access a key
The final secret segment selects trusted provider code. The namespace is
service/prod/openai. Hookfish encrypts the value before storing it and marks
successful access responses no-store.
Calling setSecret for an OAuth-backed provider returns an error. Calling
access before a static value is stored returns secret_required; it does not
return an OAuth URL.
Store and access secrets only in trusted server code. Connection metadata
routes and the browser facade never include the value.