> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/oracledb.md).

# Set up Oracle Database Credentials credentials in Duaer

Store Oracle Database Credentials connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Connect to Oracle Database <a href="#connect-to-oracle-database" id="connect-to-oracle-database"></a>

The Duaer Oracle Database Credentials API credential:

- Connection String uses Easy Connect: host:port/service_name, such as dbhost:1521/ORCLPDB1. The default localhost/orcl only fits a database on the same machine.
- User and Password are the database account. Pick Privilege only to sign in with an admin privilege such as SYSDBA; leave it empty for a normal account.
- For a database that requires mutual TLS (mTLS), such as Oracle Autonomous Database, turn on Use SSL: paste the contents of ewallet.pem from the wallet zip into Wallet Content, and fill in Wallet Password if the wallet has one.
- Keep the pool settings at their defaults.

## Oracle Database Credentials API fields in Duaer <a href="#oracle-database-credentials-api" id="oracle-database-credentials-api"></a>

In Duaer, choose Oracle Database Credentials API when you create a credential, then fill in these fields:

- User
- Password (secret)
- Connection String: The Oracle database instance to connect to. Default: localhost/orcl.
- Privilege: The privilege to use when connecting to the database. Options: SYSASM, SYSBACKUP, SYSDBA, SYSDG, SYSKM, SYSOPER, and 2 more.
- Use SSL: SSL connection with database. Default: off.
- Wallet Password (secret): The password to decrypt the Privacy Enhanced Mail (PEM)-encoded private certificate, if it is encrypted. Shown when Use SSL is on.
- Wallet Content: The security credentials required to establish a mutual TLS (mTLS) connection to Oracle Database. Shown when Use SSL is on.
- Distinguished Name: The distinguished name (DN) that should be matched with the certificate DN. Shown when Use SSL is on.
- Match Distinguished Name: Whether the server certificate DN should be matched in addition to the regular certificate verification that is performed. Default: on. Shown when Use SSL is on.
- Allow Weak Distinguished Name Match: Whether the secure DN matching behavior which checks both the listener and server certificates has to be performed. Default: off. Shown when Use SSL is on.
- Pool Min: The number of connections established to the database when a pool is created. Default: 0.
- Pool Max: The maximum number of connections to which a connection pool can grow. Default: 4.
- Pool Increment: The number of connections that are opened whenever a connection request exceeds the number of currently open connections. Default: 1.
- Pool Maximum Session Life Time: The number of seconds that a pooled connection can exist in a pool after first being created. Default: 0.
- Pool Connection Idle Timeout: The number of seconds after which idle connections (unused in the pool) may be terminated. Default: 60.
- Connection Class Name: DRCP/PRCP Connection Class.
- Connection Timeout: The timeout duration in seconds for an application to establish an Oracle Net connection. Default: 0.
- Transport Connection Timeout: The maximum number of seconds to wait to establish a connection to the database host. Default: 20.
- Keepalive Probe Interval: The number of minutes between the sending of keepalive probes. Default: 0.

Duaer nodes that use it: [Oracle Database](/integrations/builtin/app-nodes/duaer-nodes-base.oracledatabase.md).

## Save the connection in Duaer

Open Credentials and create Oracle Database Credentials. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Oracle Database Credentials secret values appear in Duaer node parameters?

No. In Duaer, Oracle Database Credentials secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Oracle Database Credentials credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Oracle Database Credentials expects, then confirm you can create credentials in that project.

