Scope levels
Global
Workspace
--workspace-id. Use this to isolate secrets between different projects or tenants.
Group
--workspace-id and --group-id. This is the most restrictive scope.
How scope resolution works
When the broker resolves a credential for a request, it considers the caller’s execution context:- If
--workspace-idand--group-idare provided, the broker first looks for group-scoped credentials - If no group-scoped credential matches, it falls back to workspace-scoped credentials
- If no workspace-scoped credential matches, it falls back to global credentials