Remote MCP servers are currently blocked on hosted Orca, so credentials for them are not used yet. See MCP tools. If you need a remote MCP server, write to support@okik.io.
Three kinds of keys
New users often mix these up. They are separate and not interchangeable:How it works
Create, use, rotate, and delete
Examples on this page assumeclient is an OpenAI client configured as in the quickstart.
mcp_server_urlmust be HTTPS and must match the MCP tool’sserver_urlexactly.- Attach the vault with
vault_ids=[vault.id]when you create the session. Attach only the vaults that session needs. - Rotate by sending a new token with
credentials.update. You never need to read the old one, and you cannot. - Responses never include the token. Keep your own copy in your secret manager if you need it again.
Credential types
What can go wrong
- No matching credential. If a tool needs a credential and no attached vault has one for that exact URL, session creation fails. Check for differences in path or a trailing slash.
- Token rejected by the server. Rotate the credential. Sessions created afterwards use the new token.
- Destination not enabled. Remote MCP servers are currently blocked on hosted Orca. A credential does not change that.
- HTTP 403
permission_denied. Writing vaults and credentials needs the admin role.
Keep it safe
- Never put tokens in prompts, function results, skills, staged files, sandbox
env, or logs. - Use the narrowest token the service offers (read-only where possible), and pair it with
allowed_toolson the agent. See MCP tools. - Protect your Orca API key. Anyone holding it can create sessions that use your vaults.