Documentation / Tool credentials
Tool credentials
Authenticate HTTP tools, MCP servers and external data requests.
Credentials store the authentication Tigy AI uses to access an external system.
Before you start
Get authentication details from the external service's documentation. You need permission to manage the tool and select or create its workspace credential.
Configure authentication
- Open the HTTP or MCP tool.
- In the credential selector, choose an existing credential or create one for the service.
- Enter the authentication type and fields required by the form, such as API key, Bearer, Basic or a custom header.
- Associate the credential with the tool and save.
- Run a test lookup and inspect the external system's result.
The header name must match the service. Authorization and a header such as X-API-Key are not interchangeable unless the server supports both.
Keep secrets out of prompts
Do not put keys in agent instructions, prompt examples or public content. Use the stored credential in request configuration. For tests, prefer an account limited to the data and actions required.
Investigate rejections
| Result | Check |
|---|---|
| 401 | Missing/expired key or incorrect authentication format |
| 403 | Recognized account without access to the resource or operation |
| Connection failure | URL and network; rotating a key does not fix an unreachable destination |
Also confirm that the credential belongs to the tool's workspace. When changing a secret at the external service, update the associated credential and repeat a test before publishing.
