> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/chroma.md).

# Set up ChromaDB credentials in Duaer

Store ChromaDB connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Choose a ChromaDB credential type <a href="#choose-a-credential-type" id="choose-a-credential-type"></a>

The Duaer Chroma vector store node supports two credentials:

- ChromaDB Self-Hosted: put the instance root, such as http://chroma:8000, in Base URL; path prefixes are not supported. If the server has auth on, fill in API Key or Token to match its config; otherwise leave both empty.
- ChromaDB Cloud: create an API key in the database settings on [Chroma Cloud](https://www.trychroma.com/) and put it in API Key. If the key is scoped to one database, leave Tenant ID and Database Name empty and Duaer resolves them.

When Duaer runs in Docker, do not use localhost for the host; use the service name or the host address.

## ChromaDB Self-Hosted <a href="#chromadb-self-hosted" id="chromadb-self-hosted"></a>

In Duaer, choose ChromaDB Self-Hosted when you create a credential, then fill in these fields:

- Base URL: The URL of your ChromaDB instance. Note that path prefixes are not supported, so the URL must point directly to the instance root. Default: http://localhost:8000.
- Authentication: Default: None. Options: None, API Key, Token.
- API Key (secret): Shown when Authentication is API Key.
- Token (secret): Shown when Authentication is Token.

When you save, Duaer tests the connection with these values.

Duaer nodes that use it: [Chroma Vector Store](/integrations/builtin/cluster-nodes/root-nodes/n8n-nodes-langchain.vectorstorechromadb.md).

## ChromaDB Cloud <a href="#chromadb-cloud" id="chromadb-cloud"></a>

In Duaer, choose ChromaDB Cloud when you create a credential, then fill in these fields:

- API Key (required, secret): Your Chroma Cloud API key.
- Tenant ID: Optional: Tenant ID (auto-resolved if API key is scoped to single DB)
- Database Name: Optional: Database name (auto-resolved if API key is scoped to single DB)
- Base URL (required): Default: https://api.trychroma.com.

When you save, Duaer tests the connection with these values.

Duaer nodes that use it: [Chroma Vector Store](/integrations/builtin/cluster-nodes/root-nodes/n8n-nodes-langchain.vectorstorechromadb.md).

## Save the connection in Duaer

Open Credentials and create ChromaDB. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do ChromaDB secret values appear in Duaer node parameters?

No. In Duaer, ChromaDB secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a ChromaDB credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields ChromaDB expects, then confirm you can create credentials in that project.

