> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/crypto.md).

# Set up Crypto credentials in Duaer

Store Crypto connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Fill in only what you use <a href="#fill-in-only-what-you-use" id="fill-in-only-what-you-use"></a>

The Duaer Crypto credential supplies keys to the Crypto node. Each action reads only the field it needs:

- Hmac: Hmac Secret.
- Sign: Private Key.
- Symmetric Encrypt and Decrypt: Encryption Passphrase, 16 or more random characters.
- Asymmetric Encrypt and Decrypt: Encryption Public Key (PEM, SPKI) to encrypt, Encryption Private Key (PEM, PKCS#8) to decrypt. RSA encrypts only small payloads, about 190 bytes with a 2048-bit key; use symmetric mode for larger data.

## Crypto fields in Duaer <a href="#crypto" id="crypto"></a>

In Duaer, choose Crypto when you create a credential, then fill in these fields:

- Hmac Secret (secret): Secret used in the Hmac action.
- Private Key (secret): Private Key used in the Sign action.
- Encryption Passphrase (secret): Passphrase for symmetric Encrypt/Decrypt. Use 16+ random characters or a strong passphrase generated by a password manager.
- Encryption Public Key (secret): RSA public key (PEM, SPKI format) used by Encrypt in asymmetric mode. RSA-OAEP-SHA256 can only encrypt small payloads (~190 bytes with a 2048-bit key); use symmetric mode for larger data.
- Encryption Private Key (secret): RSA private key (PEM, PKCS#8 format) used by Decrypt in asymmetric mode.

Duaer nodes that use it: [Crypto](/integrations/builtin/core-nodes/duaer-nodes-base.crypto.md).

## Save the connection in Duaer

Open Credentials and create Crypto. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. The matching node is under [the related node](/integrations/builtin/core-nodes/duaer-nodes-base.crypto.md).

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Crypto secret values appear in Duaer node parameters?

No. In Duaer, Crypto secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Crypto credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Crypto expects, then confirm you can create credentials in that project.

