> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/integrations/builtin/credentials/zscalerzia.md).

# Set up Zscaler ZIA credentials in Duaer

Store Zscaler ZIA connection details in Duaer for digital-organization nodes to use at runtime. Secrets are protected by the instance encryption key and are not written into node parameters.
## Fill in the Zscaler ZIA credential <a href="#get-your-credentials" id="get-your-credentials"></a>

The Duaer Zscaler ZIA API credential signs in with an admin account and API key to get a session cookie:

1. In the ZIA admin portal, open Administration > Cloud Service API Security, copy the API key, and put it in Api Key.
2. Put your Zscaler cloud API host, such as zsapi.zscalerthree.net, in Base URL.
3. Put an admin account with API access in Username and Password.

Duaer has no dedicated node for this service. In the HTTP Request node, set Authentication to Predefined Credential Type and pick the Zscaler ZIA API credential. Refer to [custom operations](/integrations/custom-operations.md).

## Zscaler ZIA API fields in Duaer <a href="#zscaler-zia-api" id="zscaler-zia-api"></a>

In Duaer, choose Zscaler ZIA API when you create a credential, then fill in these fields:

- Base URL (required)
- Username (required)
- Password (required, secret)
- Api Key (required, secret)

When you save, Duaer tests the connection with these values.

## Save the connection in Duaer

Open Credentials and create Zscaler ZIA. Fill in the key, OAuth, or server fields. After you save, digital-organization nodes reference this credential instead of putting the secret in a parameter.

Credential values are protected by the instance encryption key. If you change or lose that key, stored credentials cannot be decrypted. See the hosting notes on encryption keys. 

## Who can use this credential

Who can see or edit it follows projects and roles. Do not paste secrets into chat or variables. External vaults are covered under external secrets.
## Questions

### Do Zscaler ZIA secret values appear in Duaer node parameters?

No. In Duaer, Zscaler ZIA secrets stay in the credential. Nodes only reference the credential. Execution records should not show the plaintext secret either.

### What usually stops a Zscaler ZIA credential from saving in Duaer?

Wrong fields, an OAuth callback that does not match the instance URL, or a role that cannot create credentials. Check the fields Zscaler ZIA expects, then confirm you can create credentials in that project.

