Skip to content

Credential Handling

Store client secret values in your organization’s approved secret manager. Tenant and application IDs identify the connection but are not replacements for the secret value. Do not embed credentials in the Drive ID map.

Record the owner, expiration, and rotation plan. Follow the verified application procedure when updating credentials and test the replacement connection before retiring the old credential.

Remove passwords, access tokens, secret values, private sharing links, customer data, and confidential file contents. Capture future screenshots only in an approved test environment.

The integration’s encryption, credential storage, access controls, retention, and revocation behavior must be confirmed from the actual repository. No such claims are made here.

Related: client secrets and support.