Skip to main content

Key Value Store credentials

Create a Key Value Store credential (keyValueStore). Pairs is a repeatable collection of Key (name) and Value (value) fields. Values are password-masked in the editor and must be strings; an empty string is a valid value when a key is present.

Validation rules​

ConfigurationResult
No pairs configured, empty Pairs collection, or empty row listValid empty configuration
Exact untouched UI row: Key "", Value ""Ignored placeholder, including between populated rows
Nonblank key and Value ""Valid pair with an empty-string value
Empty key and populated value (even whitespace)Error
Whitespace-only key, including with empty valueError
Missing Key or Value field on a rowError; not an untouched placeholder
Nonstring key or value, including null, numbers, booleans, objects or arraysError; no coercion or JSON parsing
Exact key __proto__, constructor or prototypeError; reserved in all output formats
Repeated exact key nameError in all formats, including Pairs Array Only
Malformed Pairs container, non-array row list, non-object row, or unexpected fields inside Pairs/rowsError; no silent filtering

Names are compared exactly, case-sensitively, without trimming or Unicode normalization. Meaningful leading/trailing key whitespace is preserved: "region", " region " and "Region" are distinct names. Reserved names are also exact matches; " constructor " is a distinct valid key. Other object-property names such as toString and hasOwnProperty are valid. All value whitespace is preserved, including whitespace-only values. The pairs array retains configured row order after removing blank placeholders; object-property iteration follows JavaScript rules (integer-like keys may enumerate first).

Serialized shape​

For workflow/credential tooling, the configured data has this shape:

{
"pairs": {
"values": [
{ "name": "region", "value": "BC" },
{ "name": "optionalLabel", "value": "" }
]
}
}

The intentionally empty shapes are {}, { "pairs": {} }, and { "pairs": { "values": [] } }, plus lists containing only exact blank placeholders. A missing credential object, null, an array in place of a collection object, or an explicitly supplied non-array values is invalid. Validation concerns the pairs field; unrelated top-level credential metadata is not projected. Only values is allowed inside pairs, and only name/value are allowed on rows.

Row errors identify the original one-based row number, including blank rows in the count, and the failed rule. Container errors identify the credential field. Validation messages never echo supplied names or values. Correct the credential and rerun; switching output formats does not bypass validation. See error behavior.

Data exposure​

Password masking only affects the credential editor. At execution, this node deliberately includes the actual strings in values and/or pairs[*].value. It declares those paths as sensitive output fields, but this metadata does not remove values from output or restrict downstream access. Values may appear in execution data/history and may be stored or transmitted by later nodes. Configure downstream handling and execution-data retention accordingly.

This credential stores reusable configuration, not per-item mutable state. There is no remote credential test or database service to authenticate against. The node reads the credential once per execution (using item-zero context for credential expressions), then projects the same validated configuration for every input item.