External Services & API Tokens
How to create, scope, store, test, rotate, and revoke credentials for GitHub, email, Access machine auth, realtime, and safety integrations.
Credential principle
Every external integration gets its own minimum-scope credential. Human users get human identities; machines get service/API credentials. Never reuse a founder’s personal password as an application secret.
GitHub / Code Studio
- Create a GitHub token/app credential with only repository permissions needed for the intended edit/deploy workflow.
- Store it as a Cloudflare Secret (for example site-specific
GITHUB_TOKENvariables used by the code). - Configure owner/repo/branch variables exactly.
- Test against a harmless file/branch first.
- Review commit/audit trail after Command edits.
Resend / outbound email
- Create/verify the sending domain in the email provider.
- Create an API key restricted as much as the provider permits.
- Store
RESEND_API_KEYas a Cloudflare Secret. - Set sender-address variables to a real verified domain/address.
- Send a test to an internal mailbox.
- Verify SPF/DKIM/provider status before relying on production mail.
Cloudflare Access service token for Broadcast Agent
- Zero Trust → Access controls → Service credentials / Service tokens.
- Create a dedicated token for the Broadcast Agent.
- Store Client ID and Client Secret only on the trusted agent computer and in approved secret storage.
- Build an Access policy that permits that service token to the machine endpoint as needed.
- Do not add the service token to browser JavaScript.
- Rotate/revoke it if the broadcast computer is lost/rebuilt.
Realtime Worker publish secret
- Generate a random
PUBLISH_TOKEN. - Store it as a Worker secret on the realtime Worker.
- Store the same value in Command as
HVN_REALTIME_PUBLISH_TOKEN. - Set
HVN_REALTIME_CONTROL_URLto Worker origin. - Set viewer-side
HVN_REALTIME_URLwithout exposing the publish token. - Test that anonymous viewer requests cannot publish control messages.
Safety Worker credentials/config
Use an identifying NWS_USER_AGENT; use MANUAL_RUN_TOKEN to protect manual execution where enabled; keep AI/auto-TAKE settings disabled until deliberately configured. Do not treat an optional AI model binding as a source of truth.
Secret inventory record
Maintain an internal inventory containing: secret name, service, owner, purpose, where stored, created date, last rotation date, expiry date if any, and revocation procedure. Do not put the secret value in the inventory document.