> ## Documentation Index
> Fetch the complete documentation index at: https://trytilde.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Connections

> Connections store the encrypted credentials Tilde uses to reach chat, tool, and inference providers, and your own internal systems.

A connection is a Tilde primitive used by chat, tool, and inference providers. It stores encrypted credentials and related metadata, so Tilde can integrate with third-party providers and with internal systems in your organisation.

Agents never see a connection's credentials. They invoke tools, LLM providers and reverse proxies through the gateway and the gateway injects them before sending the requests upstream to the provider.

## Supported credential types

Tilde supports every common secure credential type.

| Credential type | Typical use |
| - | - |
| Static API keys and tokens | Provider API keys, bearer tokens, and custom header schemes such as `x-api-key`. |
| HTTP Basic auth | A client ID and secret sent as a Basic authorization header. |
| OAuth 2.0 authorization code | A user grants access in the browser, for confidential clients. |
| OAuth 2.0 authorization code with PKCE | The same browser flow, with a proof key for public clients. |
| OAuth 2.0 client credentials | Machine-to-machine access with no user present. |
| OAuth 2.0 JWT bearer assertion | Tilde signs an assertion with your private key and exchanges it for a token. Used for service accounts. |
| OAuth 2.0 refresh token | Tilde exchanges a stored refresh token for a new access token. |
| AWS Signature Version 4 | An IAM access key, secret, and optional session token. Tilde signs each request, for example to Amazon Bedrock. |
| Webhook signing secrets | Secrets and public keys that verify inbound provider webhooks. |

## Automatic token rotation

Tilde rotates OAuth tokens for you. It refreshes each access token shortly before it expires, safely across gateway replicas, and encrypts the new tokens before it stores them.

If a provider rejects a refresh, Tilde marks the connection as needing re-authorization, and shows that status in the UI until a user reconnects.

## Set up a connection

Users create connections in the Tilde UI. Tilde runs each provider's setup in a hosted broker frame, and only that frame holds the setup token.

<Steps>
  <Step title="Create the connection">
    In **Connections**, choose a provider and name the connection. Tilde returns a short-lived setup link.
  </Step>

  <Step title="Enter credentials or authorize">
    Enter static credentials, or start the provider's OAuth flow.
  </Step>

  <Step title="Finish setup">
    Tilde encrypts the credentials and marks the connection ready.
  </Step>
</Steps>

## Assign connections to agents

A connection does nothing until you assign it to an agent.

* Assign **inference** connections in the agent's **Inference** tab. See [Inference providers](/docs/inference-providers).
* Assign **channel** connections in the agent's **Chat providers** tab. See [Chat channels](/docs/chat-channels).
* Add **tool** connections in the agent's **Tools** tab. See [Manage tools](/docs/tools/management).
* Link **skills** to a connection, so every agent that uses it receives them. See [Manage skills](/docs/skills/management#give-skills-through-a-connection).

## How credentials are protected

Tilde encrypts every private connection value before it reaches PostgreSQL. See [Secret encryption](/docs/security/secret-encryption) for the key hierarchy, the algorithms, and how decrypted values are handled in memory.
