Skip to content

Credentials Where-used

Which flows and scripts refer to which security material, and what nobody refers to.

  • You are about to rotate or delete a credential and want every flow and script that refers to it, including through an externalised parameter.
  • You want the references to security material that is not deployed on the tenant, because those flows fail at runtime.
  • You are cleaning up and want the deployed entries nobody refers to.

References are collected by the artifact sync for the whole tenant at once. Unlike version 1, nothing has to be downloaded first. They come from:

  • adapter and step properties that name a credential or an alias, with externalised parameters resolved to their value;
  • calls such as getUserCredential("name") in Groovy and JavaScript.

What is deployed is read live from the tenant: user credentials, OAuth2 client credentials, secure parameters and keystore aliases. Filter the result by credential, flow or script name.

  • A name passed in a variable, as in getUserCredential(credentialName), is not found.
  • An externalised parameter without a value ({{param}}) and a name resolved per message (${...}) are shown as written, and never reported as “not deployed”.
  • “Not deployed” is only claimed when all four kinds of security material could be read. If the service key lacks a role, the page says the picture is incomplete.
  • “Deployed, not referenced” is a hint: a script may build the name at runtime, and other systems may use an entry too.
  • References are as of the last artifact sync.