tencent cloud

Cloud Native Intelligent Gateway

Credential Escrow

Download
Focus Mode
Font Size
Last updated: 2026-09-22 18:51:10
AI-Translated

Feature Overview

You can host existing credentials such as API keys and tokens in the MCP gateway. The gateway automatically injects these credentials into downstream requests when calling MCP Server / tools, eliminating the need for the business side to store real credentials in code. Five credential types are supported: API Key / Bearer / Basic / custom Header / Query.

Prerequisites

Gateway version 3.9.6 or later
Credentials to be hosted and target MCP services/tools have been identified.

Supported Credential Types

Type
Description
API Key
Plaintext key string
Bearer Token
Bearer token, such as GitHub PAT
Basic Auth
Username + password. The gateway automatically concatenates them into Authorization: Basic <base64>.
Custom Header
Custom Header name+value
Query Param
URL Query parameter name+value

Scenario 1: Creating a Credential

1. Log in to the AI Gateway console, go to the "Credential Hosting" menu of the gateway instance, and click the Create Credential button.
2. Fill in the corresponding fields based on the type:
Parameter
Required
Value Range/Default Value
Description
Credential Name
Yes
2-60 characters, unique within the same gateway
Supports uppercase and lowercase letters, digits, and separators ("-", "_"), cannot start with a digit or separator, and cannot end with a separator.
Credential Type
Yes
API Key/Basic Auth/Bearer Token/Custom Header/Custom Query
-
API Key Value
Required when the type is APIKey
8-60 characters
Entered in plaintext and stored encrypted.
Bearer Token Value
Required when the type is BearerToken
No more than 4096 characters
-
Username/Password
Required when the type is Basic Auth
Username no more than 256 characters, password no more than 4096 characters
-
Header Name/Value
Required when the type is Custom Header
Header name must comply with naming conventions and be no more than 128 characters; value must be no more than 4096 characters.
Header name cannot contain :.
Parameter Name/Value
Required when the type is Custom Query
Query name must comply with naming conventions and be no more than 128 characters; value must be no more than 4096 characters.
-
Description
No
No more than 200 characters
-
3. Credential values are encrypted at rest using AES-256-GCM. The list and details pages display only masked values (first 3 characters + **** + last 3 characters).

Scenario 2: Binding a Credential to an MCP Service/Tool

1. Log in to the AI Gateway console, go to the "Credential Hosting" Tab on the details page of the target MCP service, and select either Server Credential Configuration or Tool Credential Configuration for the corresponding tool.
2. Select the credential to bind and configure the injection method:
Parameter
Required
Value Range/Default Value
Description
Target Resource
Yes
MCP service or tool, supporting batch operations (1 to 50 items)
All resources in a batch operation share the same credential and injection configuration.
Injection Position
Yes
Header / Query / Body
Default Header
Injection Field Name
Yes
1 to 128 characters, such as Authorization and api_key
Injected Header Name/Query Parameter Name/Body Field Path
Force Overwrite
No, disabled by default
Enable/Disable
When the target is already bound to another credential, enable this option to replace it.
3. Binding constraints: A resource (Server/Tool) can be bound to only one credential. If a tool is not bound separately, it automatically inherits the credential configuration of its parent Server. If a tool is bound separately, the tool-level configuration takes precedence.
4. Authentication conflict check (triggered when the injection location is Header and the field name is Authorization)
MCP Service Inbound Authentication Method
Verification Result
API Key
Allow
JWT / OAuth2.0
Allow
OIDC
Blocked. Saving is prohibited.

Scenario 3: Unbinding a Credential

1. In the Server Credential Configuration or Tool Credential Configuration area, select Unbind.
2. The system checks whether the current binding relationship matches the specified credential. If they do not match, the system prompts "The credential currently bound to the resource is inconsistent with the specified credential" and rejects the operation.
3. After a Server-level credential is unbound, the inheritance relationships of all tools under it are removed simultaneously.


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback