Docs
Reference

Azure Key Vault

Move secrets to and from a Key Vault name prefix.

Move secrets to and from a Key Vault name prefix.

The connection

WhatThis provider
VendorMicrosoft Azure
Keyazure-key-vault
Availabilityavailable. You can connect it today.
Credential penv holdsazure-service-principal
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You paste a credential you already hold. penv seals it and never shows it again.

FieldLabelKindRequiredWhat it is
tenantIdDirectory (tenant) IDsecret, masked here and sealedyes
clientIdApplication (client) IDsecret, masked here and sealedyes
clientSecretClient secretsecret, masked here and sealedyes

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
vaultNameVaulttextyesnoThe vault's name alone, without the URL around it. One connection covers one vault.
basePrefixBase prefixtextyesnoThe widest secret name prefix this connection may touch. Every sync scope will sit under it.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
namePrefixSecret name prefixtextyesnoMaps onto this environment. Underscores become -U, so DATABASE_URL is DATABASE-UURL.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
Microsoft.KeyVault/vaults/secrets/readMetadata/actionevery directionyesPreview cannot list what is under this prefix.
Microsoft.KeyVault/vaults/secrets/getSecret/actionimportyesImport cannot read any value.
Microsoft.KeyVault/vaults/secrets/setSecret/actionexportyesExport cannot write anything.
Microsoft.KeyVault/vaults/secrets/deleteSecret/actionexportnoThe overwrite_and_prune policy cannot remove remote keys.
Microsoft.KeyVault/vaults/secrets/recover/actionexportnoA key pruned inside the vault's retention window cannot be written again.