> For the complete documentation index, see [llms.txt](https://docs.digibee.com/documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.digibee.com/documentation/development-cycle/build-overview/accounts.md).

# Accounts

Learn more about accounts and how they are used to safely manage credentials on the Digibee Integration Platform.

## **Overview**

Accounts provide a secure way to store sensitive information, such as passwords, private keys, and authentication tokens, without exposing these credentials directly in your integrations. By encrypting and centrally managing credentials, accounts help ensure the security of authentication processes.

Furthermore, accounts can be restricted to specific projects, ensuring that sensitive information is only accessible where it is needed. They can then be used in connectors within pipelines and capsules to authenticate and authorize access to external endpoints.

## **Managing accounts**

You can access the Accounts page from the Build page, by clicking the **Accounts** tab, or by clicking the Digibee logo in the upper-left corner, selecting **Settings**, and then finding the **Accounts** page.

The Accounts list shows the **Account Name**, **Account Type**, **Description**, **Expiration Date**, and **Running Pipelines** for each account, and can be filtered by **Account Type**, **Deprecated** status, and **Expiration status** (**Expired** or **Expiring soon**).

### **Creating an account**

On the Accounts page, click **Create new** and fill in the fields:&#x20;

| Field                         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ----------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Account name**              | A unique identifier for the account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Account type**              | The type of account. Choose from the available options.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Description**               | Additional information about the account.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Project Availability**      | Defines whether the account is available to all projects or only selected ones. On the Accounts listing page, you only see accounts available to all projects or to ones you have access to.                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Expiration date**           | <p>Sets an expiration date for the account as a reminder: it only stops working in the pipelines if this date matches the actual expiration on the external service, in which case you'll need to update the credentials and redeploy. </p><p></p><p>Enter the date in <strong>DD/MM/YYYY</strong> format (for example, <em>30/05/2030</em>). Accounts near expiration show <strong>Expires in DD/MM</strong>, and expired ones show <strong>Expired</strong>. Optional; applies only to <strong>OAuth Bearer, Private Key, Public Key, OAuth 2, Certificate Chain, Google Key, AWS V4</strong>.</p> |
| **Environment configuration** | Credentials required for the selected account type. See below how to configure each account type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

{% hint style="warning" %}
**Accounts can be permanently removed from pipelines**

An Account is removed from a pipeline if it becomes unavailable in the pipeline's project: when the pipeline is moved to a project where the account isn't allowed, or when the pipeline's project is removed from the account's list of allowed projects in its Project Availability setting.

Once removed, moving the pipeline back or re-allowing the project **will not restore it**, for security reasons. You'll need to manually add the Account back to the pipeline.
{% endhint %}

Then click **Save** to create the account.&#x20;

### **Configuring each account type**

<details>

<summary><strong>API Key</strong></summary>

**Description**\
Used when an endpoint requires an API Key.

{% hint style="info" %}
Example of connector that supports this account type includes:

* [**REST V2**](/documentation/connectors-and-triggers/connectors/web-protocols/rest-v2.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **URL-PARAM-NAME:** Query parameter where the API Key is applied
* **API-KEY:** API Key value

**Expiration for authentication tokens**

The following providers set an expiration period for their authentication tokens. For this reason, it’s necessary to update the configurations of your accounts at the end of every period.

Expiration per provider:

* **Microsoft:** Every 3 months
* **Google:** Every 6 months
* **Mercado Livre:** Every 6 months

</details>

<details>

<summary><strong>Basic</strong></summary>

**Description**\
Authentication with username and password.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**DB V2**](/documentation/connectors-and-triggers/connectors/structured-data/db-v2.md)
* [**SOAP V3**](/documentation/connectors-and-triggers/connectors/web-protocols/soap-v3.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **USERNAME:** User’s name
* **PASSWORD:** User’s password

</details>

<details>

<summary><strong>Custom Auth Header</strong></summary>

**Description**\
Used when an endpoint requires a custom authentication header.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**REST V2**](/documentation/connectors-and-triggers/connectors/web-protocols/rest-v2.md)
* [**WGet (Download HTTP)**](/documentation/connectors-and-triggers/connectors/web-protocols/wget.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **HEADER-NAME:** Header name
* **HEADER-VALUE:** Header value

</details>

<details>

<summary><strong>OAuth Bearer</strong></summary>

**Description**\
Stores an OAuth token and assigns it to the **Authorization** header in requests.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**Slack**](/documentation/connectors-and-triggers/connectors/enterprise-applications/slack.md)
* [**HubSpot: Sales and CMS**](/documentation/connectors-and-triggers/connectors/industry-solutions/hubspot.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **TOKEN:** OAuth token

</details>

<details>

<summary><strong>Private Key</strong></summary>

**Description**\
Stores a private key for authentication.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**RSA Cryptography**](/documentation/connectors-and-triggers/connectors/security/rsa-cryptography.md)
* [**SFTP**](/documentation/connectors-and-triggers/connectors/file-storage/sftp.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **KEY:** Private key
* **PASSPHRASE:** Private key password

**Example of private key**

```textproto
-----BEGIN RSA PRIVATE KEY-----
MIICWwIBAAKBgF2duc4+xxNKlMO9bUud4bzGnuATkQVX3bM/gzxISrgw7B1AzJwA
OT5UChBoIKfmISaaVVY9+/fTpI1szihSqTyemdHnbC+FcDzoK3p53C5ZJ4pL7s+G
Y7vGEa2Z/6JVder6dwJaaOtwf+DfZYiWQjvh8tfAVjVdONE/XZSxOOofAgMBAAEC
-----END RSA PRIVATE KEY-----
```

</details>

<details>

<summary><strong>Public Key</strong></summary>

**Description**\
Stores a public key for authentication with public-private key pairs.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**Digital Signature**](/documentation/connectors-and-triggers/connectors/security/digital-signature.md)
* [**RSA Cryptography**](/documentation/connectors-and-triggers/connectors/security/rsa-cryptography.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **KEY:** Public key

**Example of public key**

```textproto
-----BEGIN PUBLIC KEY-----
MIGeMA0GCSqGSIb3DQEBAQUAA4GMADCBiAKBgF2duc4+xxNKlMO9bUud4bzGnuAT
kQVX3bM/gzxISrgw7B1AzJwAOT5UChBoIKfmISaaVVY9+/fTpI1szihSqTyemdHn
-----END PUBLIC KEY-----
```

</details>

<details>

<summary><strong>OAuth 2</strong></summary>

**Description**\
Used for services that support OAuth 2.0 authorization (such as Google or Microsoft). It provides delegated access to resources without exposing user credentials.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**HubSpot: Sales and CMS**](/documentation/connectors-and-triggers/connectors/industry-solutions/hubspot.md)
* [**REST V2**](/documentation/connectors-and-triggers/connectors/web-protocols/rest-v2.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **PROVIDER:** OAuth provider
* **SCOPES:** OAuth access scopes

{% hint style="info" %}
If a custom OAuth2 provider uses a configured certificate, a password is required. This password must match the one used when uploading the certificate. For setup details, see the [OAuth2 providers documentation](/documentation/development-cycle/build-overview/accounts/new-oauth2-architecture/registration-of-new-oauth-providers.md).
{% endhint %}

**Supported providers**

* **Microsoft:** The "offline\_access" scope is mandatory on the Digibee Integration Platform. It is important to remember that this provider accepts only personal accounts.
* **Google**
* **Mercado Livre**

</details>

<details>

<summary><strong>OAuth 1</strong></summary>

**Description**

OAuth 1 is an authentication method that enables secure communication between applications without sharing user credentials. In this case, the tokens are generated directly in the platform you want to connect to, such as NetSuite. There’s no need to log in through an external provider like Google.

{% hint style="info" %}
Only the [**Oracle Netsuite**](/documentation/connectors-and-triggers/connectors/industry-solutions/oracle-netsuite.md) connector supports this account type.
{% endhint %}

**Configuration parameters**

* **OAUTH\_TOKEN:** The access token generated in the platform (for example, in NetSuite) that identifies the integration user.
* **REALM:** The account identifier or domain within the platform where the integration is performed. In NetSuite, this value usually corresponds to the account ID.
* **OAUTH\_TOKEN\_SECRET:** The secret key associated with the access token. It’s also generated in the platform and used together with the token to authenticate requests securely.

</details>

<details>

<summary><strong>Certificate Chain</strong></summary>

**Description**\
Specifies a chain of certificates for endpoints requiring 2-way SSL authentication or client certificates. Certificates must be in PEM format and in the correct order.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**CMS**](/documentation/connectors-and-triggers/connectors/security/cms.md)
* [**MongoDB**](/documentation/connectors-and-triggers/connectors/structured-data/mongodb.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **CHAIN:** Complete certificate chain
* **PASSWORD:** Private key password (if required)
* **EXPIRATION DATE:** Certificate expiration date

**Example conversion with OpenSSL**

```shell
openssl pkcs12 -in mycert_xpto.p12 -out myapp.pem
```

**Example of certificate chain**

```textproto
-----BEGIN CERTIFICATE-----
MIIEUTCCAzmgAwIBAgIBATANBgkqhkiG9w0BAQUFADBSMQswCQYDVQQGEwJVUzEj
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIEUTCCAAGVDSHVEbjhdbhjsjeiejAQUFADBSMQswCQYDVQQGEwJVUzEj
-----END CERTIFICATE-----
-----BEGIN RSA PRIVATE KEY-----
MIICWwIBAAKBgF2duc4+xxNKlMO9bUud4bzGnuATkQVX3bM/gzxISrgw7B1AzJwA
-----END RSA PRIVATE KEY-----
```

</details>

<details>

<summary><strong>Secret Key</strong></summary>

**Description**\
Used by encryption connectors.

{% hint style="info" %}
Example of connector that supports this account type includes:

* [**Orderful**](/documentation/connectors-and-triggers/connectors/industry-solutions/orderful.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **KEY:** Secret key

</details>

<details>

<summary><strong>Google Key</strong></summary>

**Description**\
Service key for accessing Google APIs.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**REST V2**](/documentation/connectors-and-triggers/connectors/web-protocols/rest-v2.md)
* [**Google Cloud Functions**](/documentation/connectors-and-triggers/connectors/google-gcp/cloud-functions.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **KEY:** Google key
* **SCOPES:** Comma-separated API access scopes. See [Google scopes](https://developers.google.com/identity/protocols/oauth2/scopes).

**Example of Google key**

```json
{
"type": "service_account",
"project_id": "project_id",
"private_key_id": "dfdsfrfr43r43r4refbcceceabf8055a12a",
"private_key": "-----BEGIN PRIVATE KEY-----\n-----END PRIVATE KEY-----\n",
"client_email": "user@DOMAIN.iam.gserviceaccount.com",
"client_id": "123456576788888899",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://accounts.google.com/o/oauth2/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/storage%40project.iam.gserviceaccount.com"
}
```

</details>

<details>

<summary><strong>Kerberos</strong></summary>

**Description**\
Stores Keytab for authentication in Kerberos environments.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**DB V2**](/documentation/connectors-and-triggers/connectors/structured-data/db-v2.md)
* [**Stream DB V3**](/documentation/connectors-and-triggers/connectors/structured-data/stream-db-v3.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **KEYTAB:** Base64-encoded Keytab file
* **PRINCIPAL:** User associated with the Keytab (for example, user\@DOMAIN)

</details>

<details>

<summary><strong>AWS V4</strong></summary>

**Description**\
Used to authenticate requests to AWS services with Signature Version 4.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**AWS Security Token Service (STS)**](/documentation/connectors-and-triggers/connectors/aws/sts.md)
* [**DynamoDB**](/documentation/connectors-and-triggers/connectors/structured-data/dynamodb.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **SERVICE-NAME:** AWS service (for example, S3, SQS)
* **ACCESS-KEY:** AWS access key
* **SECRET-KEY:** AWS secret key
* **SESSION-TOKEN:** Temporary session token (if applicable)
* **REGION:** Execution region

</details>

<details>

<summary><strong>AWS Role</strong></summary>

**Description**\
Grants an AWS user temporary access to a specific role created in AWS. To use this feature, an **AWS V4** account must be configured.

Once both account types are configured correctly, they can be used together in connectors that support the **Assume role** feature.

{% hint style="info" %}
Only the [**DynamoDB**](/documentation/connectors-and-triggers/connectors/structured-data/dynamodb.md) connector supports this feature.
{% endhint %}

**Configuration parameters**

* **ROLE-ARN:** Amazon Resource Name of the role
* **ROLE-SESSION-NAME:** Identifier for the assume role session
* **EXTERNAL-ID:** Optional identifier for cross-account operations

**Usage example**

Suppose you are using the **DynamoDB** connector and you want a specific user to access a database to retrieve some data. You don’t want this user to always have access to this database or to perform any other operations on it. In this case, you can configure a role in AWS and allow the user to temporarily assume this role to retrieve the necessary data from the database.

To achieve this, select the **AWS V4** account you want to use in the **DynamoDB** connector and activate the **Use Assume Role** parameter on the **Authentication** tab. When this option is active, you can select the **AWS Role** account that grants the user permission to perform the desired operation.

{% hint style="warning" %}
Within AWS, you must configure the AWS users who can access the role. If this configuration is not set correctly, the user of the selected **AWS V4** account won’t be able to assume the role, even if both the **AWS V4** and **AWS Role** accounts are selected in the connector.
{% endhint %}

</details>

<details>

<summary><strong>OAuth Provider</strong></summary>

**Description**\
Authorization via OAuth, supported only by the [Salesforce](/documentation/connectors-and-triggers/connectors/enterprise-applications/salesforce.md) connector.

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**Marketo**](/documentation/connectors-and-triggers/connectors/industry-solutions/marketo.md)
* [**Salesforce**](/documentation/connectors-and-triggers/connectors/enterprise-applications/salesforce.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **CLIENT-ID:** Application identifier
* **CLIENT-SECRET:** Application secret

</details>

<details>

<summary><strong>SMTP Auth and Properties</strong></summary>

**Description**

Configures SMTP credentials for sending emails with the Email V1 connector.

{% hint style="warning" %}
This account type is supported only by Email V1, which is deprecated. For Email V2 (the active version of the connector), use the **Basic** or **Azure Key** account types instead.&#x20;
{% endhint %}

**Configuration parameters**

* **HOST:** SMTP server host
* **PORT:** SMTP server port
* **USERNAME:** Email address
* **PASSWORD:** Email password
* **STARTTLS\_ENABLE:** “true” or “false” for SSL access
* **AUTH:** Authentication type

</details>

<details>

<summary><strong>NTLM</strong></summary>

**Description**\
Microsoft security protocol suite for authentication, integrity, and confidentiality. Supported via the [**SOAP V3**](/documentation/connectors-and-triggers/connectors/web-protocols/soap-v3.md) connector.

{% hint style="danger" %}
NTLM uses outdated encryption algorithms (DES, RC4) with known vulnerabilities. Replace with **Kerberos** whenever possible and implement stricter security policies.
{% endhint %}

**Configuration parameters**

* **USERNAME:** User’s name
* **PASSWORD:** User’s password
* **DOMAIN (optional):** Domain name
* **HOSTNAME (optional):** Host name

</details>

<details>

<summary><strong>Azure Key</strong></summary>

**Description**\
Used to connect to **Azure Key Vault**. Keys can be found in the **Default Directory** under **App Registrations**:

* **CLIENT-ID** and **TENANT-ID** in **Overview**
* **CLIENT-SECRET** in **Certificates & secrets**

{% hint style="info" %}
Examples of connectors that support this account type include:

* [**Azure Key Vault**](/documentation/connectors-and-triggers/connectors/azure/key-vault.md)
* [**Email V2**](/documentation/connectors-and-triggers/connectors/web-protocols/email-v2.md)

If a connector supports this account type, it will be indicated in the **Accounts** parameter in its documentation.
{% endhint %}

**Configuration parameters**

* **CLIENT-SECRET:** Client secret
* **CLIENT-ID:** Application (client) ID
* **TENANT-ID:** Directory (tenant) ID

</details>

### **Editing an account**

To edit an account, go to the **Accounts list** and click the row of the account you want to edit.

You can:

* Update the description.
* Mark the account as deprecated. [Learn more about deprecating an account](#deprecating-an-account).
* Define new rules for **Project Availability**.
* Update credentials for all environments. Sensitive credentials won't be visible, but you can add new ones.
* View all pipelines that use the account. If you edit the account, any deployed pipelines must be redeployed to apply the changes.

After editing the account, click **Save**. A confirmation window appears, and you must click **Edit** to confirm the changes.

All changes are applied immediately to pipelines that use the account and have not yet been deployed. For deployed pipelines, we recommend redeploying them after editing the account to prevent issues and keep the pipelines up to date.

### **Deprecating an account** <a href="#deprecating-an-account" id="deprecating-an-account"></a>

Deprecating an account makes it unavailable for new pipelines or new pipeline versions. Existing deployments will keep working unless redeployed.

To deprecate an account:

1. In the **Accounts list**, click the row of the account you want to deprecate.&#x20;
2. Enable the **Deprecated** toggle.
3. Click **Save**.

{% hint style="warning" %}
This action is irreversible.
{% endhint %}

### **Deleting an account**

Deleting an account permanently removes it from the Platform. You cannot delete accounts that are currently used in pipelines, whether deployed or not. To proceed, remove or replace the account in all pipelines before deleting it.

To delete an account:

1. In the **Accounts list**, click the three dots of the account you want to delete.
2. Select **Delete**.
3. Confirm the action in the pop-up window.

{% hint style="warning" %}
This action is irreversible.
{% endhint %}

### **Using accounts**

Accounts provide secure access to external services within pipelines and capsules, through connectors that support the **Account** field. When a connector requires one, this field appears in its configuration form so you can select the appropriate account for that integration.

{% hint style="info" %}
When you select an account in a connector's configuration form, only the accounts allowed in the pipeline's project are shown, keeping sensitive credentials restricted to authorized projects.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.digibee.com/documentation/development-cycle/build-overview/accounts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
