This card carries the content/docs half of #20590. Filing gate: ④ a coordination node, a per-layer child in the #20618 pattern.
Why this is owed
Triage's direction on #20590 (5891721503) is A, taken whole. A literal credential typed into a flow http node's headers, a connector node's connectorConfig.input, or an http url is served at member-level definition reads (measured REACHED in 5890702006, with exposure 0 here and in hotcrm). So the remedy steers authors to a declarative connector's credentialRef and warns at author time. ⛔ Nothing is withheld. Clause-②: no for the guidance faces.
The deliverable (triage's text, point 1)
content/docs/automation/flows.mdx, the http section, says that a flow definition is served to every member who can read flows, and routes an outbound credential to a declarative connector's credentialRef. That page already links credentialRef only from the connector paragraph.
- Its secret-bearing incoming-webhook url example (about
:266 on main) is replaced by the connector route, or says plainly that the url is served. That is position 6's guidance half.
content/docs/automation/connectors.mdx's rest provider request action accepts headers in its input with no word about credentials. One line there, pointing to auth.credentialRef, closes the same gap.
Dedupe
MCP search_issues (a read), objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:
Dedupe words: flows.mdx http credential · webhook url secret docs example
This card carries the
content/docshalf of #20590. Filing gate: ④ a coordination node, a per-layer child in the #20618 pattern.domain:servicesexecution seat ([PM seat] domain:services — 🟢 os-justin #6021,session_01XY5uCwTjZj7884yYtyur4H).domain:devx). ⛔ Not a claim.Why this is owed
Triage's direction on #20590 (
5891721503) is A, taken whole. A literal credential typed into a flowhttpnode'sheaders, a connector node'sconnectorConfig.input, or anhttpurl is served at member-level definition reads (measured REACHED in5890702006, with exposure 0 here and in hotcrm). So the remedy steers authors to a declarative connector'scredentialRefand warns at author time. ⛔ Nothing is withheld.Clause-②: nofor the guidance faces.The deliverable (triage's text, point 1)
content/docs/automation/flows.mdx, thehttpsection, says that a flow definition is served to every member who can read flows, and routes an outbound credential to a declarative connector'scredentialRef. That page already linkscredentialRefonly from the connector paragraph.:266onmain) is replaced by the connector route, or says plainly that the url is served. That is position 6's guidance half.content/docs/automation/connectors.mdx'srestproviderrequestaction acceptsheadersin its input with no word about credentials. One line there, pointing toauth.credentialRef, closes the same gap.Dedupe
MCP
search_issues(a read),objectstack-ai/objectstack, open and closed, run 2026-09-29 by this seat:sys_webhook.definition_json#7799, [security] sys_http_delivery.headers_json still stores webhook credentials in cleartext — and every services-lane shape for fixing it is structurally wrong #8118 and [security] Webhook HMAC signing secrets are persisted in cleartext on everysys_http_deliveryrow #7722 are all closed; they are webhook-object storage decisions ([security] decide explicitly: a webhook URL can BE the credential (Slack/Discord-style endpoints), and it is stored plain on two objects #8025 ruled a webhook url can BE the credential, for webhook objects), not the flows guide.Dedupe words:
flows.mdx http credential·webhook url secret docs example