Skip to main content

Manage Credentials

Create, test, edit, and delete the credentials Luumen uses to authenticate, choose where each secret is stored, and decide who else can use it.

Written by Braden Ericson

A credential holds the username and secret Luumen uses to authenticate to a host. Keeping credentials separate from hosts means one service account can serve fifty servers, and rotating it is one edit rather than fifty.

Credentials

Open Credentials in the left navigation. Each row shows the credential's Name, its Storage (Local or Luumen Cloud), its scope, and how many hosts use it. The list filters by Scope: Personal or Workspace.

The credentials list showing each credential's name, storage, and host count

Personal and Workspace Credentials

Every credential has a scope, fixed when you create it.

Personal credentials are yours alone. Nobody else in the workspace can see or use them, and they do not appear in anyone else's credential picker. This suits access tied to you as an individual.

Workspace credentials are available to everyone with access to that workspace. Use this for shared service accounts, so a new teammate can connect on their first day without being handed a secret.

The Scope control appears only for Owners and Admins on Team and Enterprise. Free and Pro plans creates personal credentials only. Scope cannot be changed after creation, so to move a shared account into workspace scope, create it again and reassign the hosts.

Add a Credential

Start from the Credentials page, or click Add credential while adding or editing a host.

  1. Give it a Name you will recognize in a dropdown six months from now, such as prod-web deploy key. Names are compared ignoring case and spacing, and Luumen warns if the name is already taken.

  2. Choose the Scope if the control is shown.

  3. Enter the Username on the target host.

  4. Pick the authentication method.

Method

What it is

Where the secret lives

Works for

Local SSH Keychain

A key already on your computer, found through your SSH agent or ~/.ssh.

Your machine only. Never uploaded.

SSH. Personal scope only.

Password

A password, with a Storage choice.

Local keeps it on this machine only. Luumen Cloud encrypts it at rest and syncs it across your devices, which is what allows a workspace credential to be shared.

SSH and WinRM.

Upload Private Key

The private key itself, pasted or uploaded from a file.

Your workspace, encrypted.

SSH.

The add credential form showing name, username, authentication, scope, and storage

Saving shows Credential created with a Test now action so you can verify it immediately.

Secrets Are Write-Only

Once saved, a password or private key cannot be read back out of Luumen. You can only test it, reassign it, or replace it.

Test a Credential

Open a credential and click Test. Luumen asks you to select one of the hosts that uses the credential, authenticates to it, and reports the result or the exact error. Test works for SSH only, so testing a credential used for a Windows host always reports a failure. A credential attached to no host cannot be tested; attach it to a host first, or test from the host's own form.

Edit a Credential

Editing a credential applies to every host using it, which means an edit can affect many connections at once. To change one host only, make a new credential and reassign that host.

Delete a Credential

Deleting opens a confirmation. If any host still uses the credential, deletion is blocked and a Delete credential dialog lists those hosts so you can reassign them first.

Rotating a Secret

Put the new secret in place on the hosts, edit the credential in Luumen to replace it, test against one host, then retire the old secret on the hosts. Every host using the credential picks up the change at its next connection.

Related articles

Did this answer your question?