Introducing Credential Vault
What's New
The Credential Vault lets you store and manage external credential sets used to access customer systems and trading-partner portals — in one place, encrypted, instead of over email, chat, or a shared password manager.
Credentials stored in the vault can be used to import historical data, configure a system of record, share files, or run off-platform testing. Every credential set records what it's tied to and why it exists, so there's always a clear answer to "what is this for?" — for you and for anyone on your team picking the work up later.
What You Can Store
| Type | Covers |
|---|---|
| Login | Username and password credentials — EDI provider and partner portal access |
| API | API keys, tokens, and other programmatic secrets, including NetSuite and custom credential types |
Each set carries a scope — whether it serves your whole organization, one trading partnership, or several — and a purpose: historical data extraction, connector configuration, off-platform testing, or file sharing access.
How Your Credentials Are Protected
The vault is built so that secrets stay unseen, and so that every time one is read there's a record of it.
- Encrypted at rest. Secret values are encrypted before they're stored. Plain text values are never persisted and never written to logs.
- Masked by default. Values display as dots. Revealing one is a deliberate act, not the default state.
- Copy without revealing. Click the Copy icon and the value goes straight to your clipboard while the field stays masked — so you can move a secret into another system without it appearing on screen.
- Reading is always recorded. Copying a secret is written to the audit log exactly as revealing it is. The two are treated as equivalent, so reading a credential is never invisible.
- Some values can never be read back. A few fields — such as the private key on an OAuth 2.0 credential set — are used directly by Orderful's systems and are never shown in plain text or copied, by anyone, including an Org Admin. They display as populated with no Reveal or Copy option, and can still be overwritten at any time.
Credential values are never returned across organizations, and are never exposed to external AI tools.
Read-Only Credential Sets
Some credential sets are created and maintained automatically by a connector — during NetSuite onboarding, for example — rather than entered by a person. These appear in the vault like any other set but are read-only: you can view them, and they can't be edited or deleted. If one needs to change, contact the team responsible for that integration.
How to Access
- Sign in to Orderful.
- Click your avatar and select Settings.
- Click Credential Vault.
Use the Login and API filter tabs to browse by category, or the search bar to find a credential set by name.
Learn more here: Credential Vault

