---
title: "Configure credentials"
description: "Choose the credential path for an MCP endpoint, agent, judge, or uploaded run."
---

> M3 v0.2.19 · commit 3151b22dd397b98a1d1b2ae87e4f0c44b3c9401f.


# Configure credentials

Choose the task and continue to its guide:

| Task | Credential path | Next guide |
| --- | --- | --- |
| Pass a credential to a stdio MCP server | `SecretReference` in the server environment | [Pass a credential to a stdio MCP server](https://m3.sineframe.com/docs/guides/credentials/endpoints.md) |
| Authenticate a native agent | Explicit `credential_env` mapping; Codex can also reuse eligible host authentication | [Configure agent harnesses](https://m3.sineframe.com/docs/guides/agents/harnesses.md) |
| Pass an environment value to an ACP agent | `${ENV_NAME}` in the ACP manifest | [Configure ACP agents](https://m3.sineframe.com/docs/guides/agents/acp.md) |
| Authenticate an LLM judge | `M3_JUDGE_API_KEY` or a judge-scoped mapping | [Use an LLM judge](https://m3.sineframe.com/docs/guides/evaluations/judges.md) |
| Upload an M3 run | `M3_ACCESS_TOKEN` in an explicitly trusted job | [Run M3 in GitHub Actions](https://m3.sineframe.com/docs/guides/ci/github-actions.md) |

For the exact resolution and failure behavior, see the [credential reference](https://m3.sineframe.com/docs/reference/credentials.md). Project environment-file behavior is in [configuration](https://m3.sineframe.com/docs/reference/configuration.md).
