Configure credentials
Choose the task and continue to its guide:
| Task | Credential path | Next guide |
|---|---|---|
| Pass a credential to a stdio MCP server | SecretReference in the server environment | Pass a credential to a stdio MCP server |
| Authenticate a native agent | Explicit credential_env mapping; Codex can also reuse eligible host authentication | Configure agent harnesses |
| Pass an environment value to an ACP agent | ${ENV_NAME} in the ACP manifest | Configure ACP agents |
| Authenticate an LLM judge | M3_JUDGE_API_KEY or a judge-scoped mapping | Use an LLM judge |
| Upload an M3 run | M3_ACCESS_TOKEN in an explicitly trusted job | Run M3 in GitHub Actions |
For the exact resolution and failure behavior, see the credential reference. Project environment-file behavior is in configuration.