Manage → Configuration → Service account credentials
Reached from Manage via the Configuration entry at the bottom of the browse tree.
Service account credentials used by MisterShell to authenticate with your resources. Each credential has a type that determines which fields are shown in the form. A single Username / Password credential works across SSH, RDP, web, database, and VNC targets, with optional Enable Password (privileged-exec on network devices) and Domain (Windows / AD) fields. Other types cover key- and API-based authentication — SSH Key, AWS Credentials, Azure Service Principal, and Kubeconfig. No Authentication is a built-in entry for targets that need no credentials; it cannot be created, edited, or deleted.
Your saved template credentials and independent personal/team credentials live under Account → Personal Vault. This tab manages the service account credentials assigned to resources and used by automation.
What you can do
- Create, edit, and delete service account credentials.
- Filter by credential type and search by name or description.
- Choose whether a credential is used directly or requires personal credentials for interactive sessions, saved in the account or entered at connection time.
Common tasks
Create a credential
- Click Create service account credential at the top right.
- Fill the form:
- Name — a descriptive label (e.g., “Corporate Linux root”).
- Credential type — pick the credential type. The type cannot be changed after creation.
- Description — optional notes visible to other users.
- Require user credential for interactive sessions — see Sharing model below.
- Service account details — fields specific to the selected type (password, private key, access key, etc.). Secret fields are masked and stored encrypted.
- Click Create.
Edit a credential
- Click the blue pencil icon on the row.
- Update any field except the type.
- Click Update. Re-entering a secret is optional; leaving it blank keeps the stored value.
Delete a credential
- Click the red trash icon.
- Confirm in the dialog.
A credential cannot be deleted while resources reference it. Assign a replacement to those resources before deleting it.
The built-in No Authentication entry has no edit or delete controls — it is a system-provided credential that always exists and cannot be changed.
Sharing model
The Interactive sessions column and Require user credential for interactive sessions setting describe how interactive users authenticate:
| Interactive sessions | Meaning |
|---|---|
| Service account | The setting is off. Interactive sessions use the same service account credential as MisterShell’s resource operations. |
| User credential required · Template | The setting is on. The service account credential also becomes a template. Each user supplies their own credential when connecting, or saves it beforehand in Account → Personal Vault. |
| No authentication | The built-in entry for resources that require no authentication. |
Service account details remain required when template mode is enabled. Snapshots, automation and MCP device actions continue using those details. Users’ saved credentials are separate and are not combined with the service account values.
This setting applies to all resources using this credential. Turning it off makes new interactive connections use the service account. Resource permissions, transport trust and connection/file policies remain authoritative.
With template mode enabled, a user’s saved credential is used automatically. Without one, Authentication required offers Enter manually or a compatible personal/team credential through Use vault. A vault selection can have a different credential type if the resource and connection mode support it; it does not save a credential for the template.
For supported live connections, Remember this credential saves a manual entry after authentication succeeds. Explicit authentication failures reopen the prompt. If a saved credential fails, Update saved credential is checked and read-only: submitting updates that user’s saved credential before reconnecting. Web connections do not support automatic saving or authentication-failure correction. Users can also edit or clear their saved credentials in Personal Vault.
Reusable terminal/file sessions can be attached without another prompt. File browsing and transfers use their own credential prompts; the live-session remember/correction behavior does not apply universally. Transfer batches open separate transports and can ask again. Supported up-front tokens/OTP values can be entered; this does not add multi-round challenge/response support.
A template requires each operator to supply credentials, but does not guarantee a unique remote account: users may select the same team vault entry. Session records identify the MisterShell operator; target-side attribution depends on the remote login used.
Table columns
| Column | Notes |
|---|---|
| Name | The credential’s display name. |
| Type | Badge showing the credential type. The built-in entry shows a System — No Authentication badge instead. |
| Interactive sessions | Service account, User credential required with a Template badge, or No authentication. |
| Description | Free-text description. |
| Resources | Number of resources using this service account credential; select it to review and reassign resources. |
| Actions | Edit and Delete buttons (hidden for the built-in No Authentication entry). |
Permissions
- Read:
app.credentials.read. - Create / edit:
app.credentials.write. - Delete:
app.credentials.delete.