# Conflicts: # .agents/notes/implemented/feature/2026-07-20-dsh-cli-personal-config.i18n.yaml # .agents/notes/implemented/feature/2026-07-20-dsh-cli-personal-config.md # .agents/notes/implemented/feature/2026-07-20-dsh-cli-personal-config.zh.md # apps/cli/config/base.cordis.yml # apps/cli/package.json # apps/cli/reference/README.i18n.yaml # apps/cli/reference/README.md # apps/cli/reference/README.zh.md # apps/cli/src/app-cli-entry.ts # apps/cli/src/args.ts # apps/cli/src/bin.ts # apps/cli/src/config.ts # apps/cli/src/dump-config.ts # apps/cli/src/headless.ts # apps/cli/src/web.ts # apps/cli/tests/args.spec.ts # apps/cli/tests/built-bin.e2e.ts # apps/cli/tests/headless-shutdown.e2e.ts # apps/cli/tsconfig.json # docs/user/guide/config.i18n.yaml # docs/user/guide/config.md # docs/user/guide/config.zh.md # examples/mcp-memory/README.i18n.yaml # examples/mcp-memory/README.md # examples/mcp-memory/README.zh.md # packages/bundle/web-app/cordis.patch.yml # packages/cordis/repository-plugin/README.i18n.yaml # packages/cordis/repository-plugin/README.md # packages/cordis/repository-plugin/README.zh.md # packages/credentials/credentials-local/README.i18n.yaml # packages/credentials/credentials-local/README.md # packages/credentials/credentials-local/README.zh.md # packages/ui/app-boot/README.i18n.yaml # packages/ui/app-boot/README.md # packages/ui/app-boot/README.zh.md # packages/ui/app-boot/src/index.ts # packages/ui/app-boot/tests/config-reload.spec.ts # packages/ui/app-boot/tests/user-patches.spec.ts # pnpm-lock.yaml
credentials/ — credential references
English | 中文
The credential capability family separates reference resolution from its provider:
| Package | Role | ctx key |
|---|---|---|
credentials/ |
Credential-reference seam | ctx.credentials |
credentials-local/ |
Environment and local-file provider | registers ctx.credentials |
Configuration carries references, not secret values. Consumers resolve those references at their operation boundary; the child READMEs own mutation, precedence, and storage semantics.