Launch Week 3: Five days of launches

Authorization for AI Connections

Configure authentication and secrets management for your AI connection endpoint.

Included on the Enterprise plan. Book a demo, opens in a new tab. Not included on the Team plan. Not included on the Starter plan. Not included on the Free plan.

Overview

The Authentication tab of your AI Connection lets you configure authentication for requests to your AI app endpoint. You pick an Authentication Type, then choose whether its credentials are entered Inline or read from a Secrets Manager.

Configure authentication for your endpoint

Secrets Manager

A secrets manager lets you securely retrieve authentication credentials at runtime from a cloud vault, instead of storing them directly on the platform.

To use a secrets manager:

  1. Select an authentication type
  2. Switch Credentials from Inline to Key Vault (Azure Key Vault)
  3. Enter your Vault URL (e.g., https://your-vault.vault.azure.net)
  4. Enter your Vault Tenant ID, Vault Client ID, and Vault Client Secret to authenticate to the vault

Authentication

Select an authentication type from the Authentication Type dropdown:

TypeDescription
Not setNo authentication is applied (the default)
Auth0Exchanges client credentials for a Bearer token via Auth0's OAuth2 client credentials flow
HMACComputes an HMAC-SHA256 signature of the request payload and sends it as a header
Azure ADGets a Bearer token from Microsoft Entra ID with the client credentials or password (ROPC) grant
OAuth2 Client CredentialsGets a Bearer token from your identity provider's Token URL, authenticating with a client certificate (mTLS) or a client secret

For a step-by-step Azure AD or Auth0 setup, see Client Credentials AI Connections. WebRTC voice connections get a LiveKit option instead (see Voice).

Auth0 requires the following fields:

FieldDescription
Auth0 DomainYour Auth0 tenant domain (e.g., your-tenant.auth0.com)
AudienceThe API identifier this token is authorized to access
Client ID / Client ID Secret NameYour Auth0 application client ID, or the name of the secret in your vault if using a secrets manager
Client Secret / Client Secret Secret NameYour Auth0 application client secret, or the name of the secret in your vault if using a secrets manager

HMAC requires the following fields:

FieldDescription
Header KeyThe HTTP header name where the signature is sent (e.g., X-Signature)
Signature Prefix (optional)An optional prefix prepended to the signature (e.g., sha256=)
Secret Key / Secret NameThe signing key, or the name of the secret in your vault if using a secrets manager

Next Steps

With authorization configured, your AI connection can securely reach protected endpoints. Next, learn how to handle multi-turn evaluations and link results back to traces.

Scaling beyond prototype?For teams evaluating Confident AI in productionTalk to us

Last updated on

Built byConfident AI