Skip to main content
A connection is a Tilde primitive used by chat, tool, and inference providers. It stores encrypted credentials and related metadata, so Tilde can integrate with third-party providers and with internal systems in your organisation. Agents never see a connection’s credentials. They invoke tools, LLM providers and reverse proxies through the gateway and the gateway injects them before sending the requests upstream to the provider.

Supported credential types

Tilde supports every common secure credential type.

Automatic token rotation

Tilde rotates OAuth tokens for you. It refreshes each access token shortly before it expires, safely across gateway replicas, and encrypts the new tokens before it stores them. If a provider rejects a refresh, Tilde marks the connection as needing re-authorization, and shows that status in the UI until a user reconnects.

Set up a connection

Users create connections in the Tilde UI. Tilde runs each provider’s setup in a hosted broker frame, and only that frame holds the setup token.
1

Create the connection

In Connections, choose a provider and name the connection. Tilde returns a short-lived setup link.
2

Enter credentials or authorize

Enter static credentials, or start the provider’s OAuth flow.
3

Finish setup

Tilde encrypts the credentials and marks the connection ready.

Assign connections to agents

A connection does nothing until you assign it to an agent.
  • Assign inference connections in the agent’s Inference tab. See Inference providers.
  • Assign channel connections in the agent’s Chat providers tab. See Chat channels.
  • Add tool connections in the agent’s Tools tab. See Manage tools.
  • Link skills to a connection, so every agent that uses it receives them. See Manage skills.

How credentials are protected

Tilde encrypts every private connection value before it reaches PostgreSQL. See Secret encryption for the key hierarchy, the algorithms, and how decrypted values are handled in memory.