> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/miro.md).

# Set up Miro credentials in Duaer

Store Miro connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Create a Miro app <a href="#create-a-miro-app" id="create-a-miro-app"></a>

The Duaer Miro OAuth2 API credential:

1. In Miro, open Profile settings > Your apps, create an app, set Redirect URI for OAuth2.0 to the Duaer OAuth Redirect URL, and tick boards:read and boards:write.
2. Put Client ID and Client Secret in the credential. Scope defaults to boards:read boards:write and must match the app. Click Connect my account and pick the team.

Duaer has no dedicated node for this service. In the HTTP Request node, set Authentication to Predefined Credential Type and pick the Miro OAuth2 API credential. Refer to [custom operations](/integrations/custom-operations.md).

## Miro OAuth2 API fields in Duaer <a href="#miro-oauth2-api" id="miro-oauth2-api"></a>

In Duaer, choose Miro OAuth2 API when you create a credential, then fill in these fields:

- Client ID (required)
- Client Secret (required, secret)
- Scope (required): OAuth scopes to request. See Miro scopes documentation (https://developers.miro.com/reference/scopes). Default: boards:read boards:write.

Duaer uses the OAuth2 Authorization Code grant for this type.

In the provider’s app settings, register the OAuth Redirect URL that the Duaer credential dialog shows (https://<your-duaer-host>/rest/oauth2-credential/callback). Then click Connect my account in Duaer and approve access.

Optional settings shared by every Duaer OAuth2 credential: Ignore SSL Issues (Insecure), Token Expired Status Code, Encrypted Tokens (JWE), JWKS URI. They are described under [OAuth2 API](/integrations/builtin/credentials/httprequest.md#oauth2-api).

## Save the connection in Duaer

Open Credentials and create Miro. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Miro secret values appear in Duaer node parameters?

No. In Duaer, Miro secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Miro credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Miro expects, then confirm you can create credentials in that project.

