Output.aiプロジェクト用の暗号化されたログイン認証情報(ユーザーIDやパスワードなど、アクセスに必要な情報)を初期化します。 次のような場合に使用: - ログイン認証情報を初めて設定する - 環境ごとに異なる認証情報を追加する - ワークフロー(一連の処理の流れ)ごとの認証情報を追加する
Initialize encrypted credentials for an Output.ai project. Use when setting up credentials for the first time, adding environment-specific credentials, or adding per-workflow credentials.
npx output credentials init コマンドを実行すると、以下の2つのファイルが生成されます。
.key) — 復号化に使用するシークレット。絶対にコミットしないでください。.yml.enc) — クレデンシャルのストア。コミットしても安全です。# グローバルクレデンシャル(最も一般的)
npx output credentials init
# 環境固有
npx output credentials init -e production
npx output credentials init -e staging
# ワークフロー単位のクレデンシャル(該当ワークフローに対してグローバル設定を上書き)
npx output credentials init -w my_workflow
# 既存ファイルを強制的に上書き
npx output credentials init --force
config/
├── credentials.key ← .gitignore に追加すること
└── credentials.yml.enc ← コミットしても安全
config/credentials/
├── production.key ← .gitignore に追加すること
└── production.yml.enc ← コミットしても安全
src/workflows/{name}/
├── credentials.key ← .gitignore に追加すること
└── credentials.yml.enc ← コミットしても安全
初期化後、暗号化された YAML には以下のテンプレートが含まれます。
anthropic:
api_key: ""
openai:
api_key: ""
_env:
ANTHROPIC_API_KEY: anthropic.api_key
OPENAI_API_KEY: openai.api_key
_env セクションは、ワーカー起動時にクレデンシャルを環境変数へ自動的に紐付けます。
詳細は output-credentials-env-vars を参照してください。
npx output credentials edit # 復号化された YAML を $EDITOR で開く
空の値を入力し、保存してエディタを閉じてください。ファイルは自動的に再暗号化されます。
echo "*.key" >> .gitignore
echo "config/credentials.key" >> .gitignore
または、.gitignore に以下を追記してください。
# クレデンシャルの復号化キー — 絶対にコミットしないこと
*.key
config/credentials.key
config/credentials/*.key
src/workflows/*/credentials.key
CI/CD パイプラインでは、ファイルをコミットする代わりに、キーを環境変数として渡してください。
# CI/CD 環境で設定する
OUTPUT_CREDENTIALS_KEY=<key-value>
# 環境固有
OUTPUT_CREDENTIALS_KEY_PRODUCTION=<key-value>
# ワークフロー単位
OUTPUT_CREDENTIALS_KEY_MY_WORKFLOW=<key-value>
キーの値は .key ファイルの内容です。
config/credentials.key が作成されている(または環境固有のバリアント)config/credentials.yml.enc が作成されている.key ファイルが .gitignore に追加されているnpx output credentials edit を実行してシークレットの値を入力済みであるnpx output credentials show で復号化が正常に動作することを確認済みであるoutput-credentials-edit — クレデンシャルの値の入力と管理output-credentials-env-vars — クレデンシャルを環境変数へ紐付けるoutput-dev-credentials — クレデンシャルシステム全体のリファレンスThe npx output credentials init command generates two files:
.key) — the decryption secret. Never commit this..yml.enc) — the credentials store. Safe to commit.# Global credentials (most common)
npx output credentials init
# Environment-specific
npx output credentials init -e production
npx output credentials init -e staging
# Per-workflow credentials (overrides globals for that workflow)
npx output credentials init -w my_workflow
# Force overwrite existing files
npx output credentials init --force
config/
├── credentials.key ← Add to .gitignore
└── credentials.yml.enc ← Safe to commit
config/credentials/
├── production.key ← Add to .gitignore
└── production.yml.enc ← Safe to commit
src/workflows/{name}/
├── credentials.key ← Add to .gitignore
└── credentials.yml.enc ← Safe to commit
After init, the encrypted YAML contains this template:
anthropic:
api_key: ""
openai:
api_key: ""
_env:
ANTHROPIC_API_KEY: anthropic.api_key
OPENAI_API_KEY: openai.api_key
The _env section wires credentials to environment variables automatically at worker startup. See output-credentials-env-vars for details.
npx output credentials edit # Opens $EDITOR with decrypted YAML
Fill in the empty values, save, and close. The file is re-encrypted automatically.
echo "*.key" >> .gitignore
echo "config/credentials.key" >> .gitignore
Or add to your .gitignore:
# Credentials decryption keys — never commit
*.key
config/credentials.key
config/credentials/*.key
src/workflows/*/credentials.key
In CI/CD pipelines, pass the key as an environment variable instead of committing the file:
# Set in your CI/CD environment
OUTPUT_CREDENTIALS_KEY=<key-value>
# Environment-specific
OUTPUT_CREDENTIALS_KEY_PRODUCTION=<key-value>
# Per-workflow
OUTPUT_CREDENTIALS_KEY_MY_WORKFLOW=<key-value>
The key value is the contents of the .key file.
config/credentials.key created (or env-specific variant)config/credentials.yml.enc created.key files added to .gitignorenpx output credentials edit run to fill in secret valuesnpx output credentials show verifies decryption worksoutput-credentials-edit — Fill in and manage credential valuesoutput-credentials-env-vars — Wire credentials to environment variablesoutput-dev-credentials — Full credentials system reference原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。