Penv Cloud
Start free
Docs
Reference

Phase

Sync an environment with one folder of a Phase app environment, in either direction.

Sync an environment with one folder of a Phase app environment, in either direction.

Connection

WhatThis provider
VendorPhase
Keyphase-secrets
Availabilityavailable. You can connect it today.
Credential we holdphase-token
Values read backyes
Activationimmediate

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

immediate. The running app sees a new value at once.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

Paste a credential from the vendor. We seal it and never show it again.

FieldLabelKindRequiredWhat it is
tokenService account tokensecret; we mask it here and seal ityesIn the Phase console, open Access, then Service Accounts, create a token, and add the account to the app. The Service role grants everything a sync needs.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
hostInstance URLtextnoyesLeave empty for Phase Cloud. For your own instance, the address you open the console at. It must be reachable from the internet.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
appIdApp IDtextyesnoFrom the app's Settings page in the Phase console.
environmentEnvironmenttextyesnoThe environment name as the app lists it.
pathFoldertextnoyesOne folder per sync. We do not walk subfolders, and pruning deletes every secret in this folder that this environment lacks. Starts at /.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
Apps:readevery directionyesWe cannot confirm the token or see which apps have server-side encryption.
server-side-encryptionevery directionnoPhase refuses API access to an app without server-side encryption. Turn it on in the app's Settings page.
Secrets:readevery directionyesPreview cannot list the folder, and import cannot read a value.
Secrets:createexportyesExport cannot add a secret.
Secrets:updateexportyesExport cannot change a secret that already exists.
Secrets:deleteexportnoPrune cannot remove a secret.