# Managing secrets and API keys

Add provider keys only to dedicated agent or connection fields, restrict the associated agent and tools, rotate exposed keys at the provider, and retest after replacement.

![Managing secrets and API keys in Foxora v5.0.3](/docs/images/v5.0.3/settings/models.webp)

## Where this lives

Open the relevant section under **Settings → Permissions** or **Settings → Data**.

Foxora security is layered across account authentication, local project access, session autonomy, agent tools, browser and computer control, connected services, and local data storage.

> **Safety:** No autonomy mode can make an external action reversible. Use separate test environments, least privilege, independent verification, and prompt incident response for suspected credential exposure.

## Steps

1. Open the relevant section under **Settings → Permissions** or **Settings → Data**.
2. Add provider keys only to dedicated agent or connection fields.
3. Restrict the associated agent and tools.
4. Rotate exposed keys at the provider, and retest after replacement.
5. **Confirm the result.** Review the transcript and external audit records, inspect authorized devices and connections, and test that revoked access no longer works.

## Choose the right path

- Use local sessions and Memory Den for device-resident work.
- Use Composio authorization for supported plugin accounts.
- Use an agent’s dedicated BYOK field for model-provider keys.


## Confirm it worked

- Review the transcript and external audit records, inspect authorized devices and connections, and test that revoked access no longer works.
- The screen, command, file, run, or destination named in this guide reflects the expected state.
