> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/daytona.md).

# Set up Daytona credentials in Duaer

Store Daytona connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Get a Daytona API key <a href="#get-an-api-key" id="get-an-api-key"></a>

No Duaer node uses this credential; Duaer orgifyDesk does. Open Code sandbox in the Duaer orgifyDesk settings and fill it in as below.

1. In the [Daytona dashboard](https://app.daytona.io/), open Keys and create an API key.
2. Under Code sandbox, choose Daytona, put https://app.daytona.io/api (or your self-hosted Daytona address) in API URL and the key in API Key, then save.

Daytona is a paid third-party hosted service, so code and digital organization data leave your network. To stay on your own infrastructure, use the sandbox service on your own Docker host instead.

## Daytona fields in Duaer <a href="#daytona" id="daytona"></a>

In Duaer, choose Daytona when you create a credential, then fill in these fields:

- API URL (required)
- API Key (required, secret)

## Save the connection in Duaer

Open Credentials and create Daytona. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Daytona secret values appear in Duaer node parameters?

No. In Duaer, Daytona secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Daytona credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Daytona expects, then confirm you can create credentials in that project.

