# Working with secrets and sensitive values with the Uptime App

**URL:** <https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126>\
**Category:** Synthetics\
**Created:** [October 20, 2022, 2:31pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126 "2022-10-20T14:31:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marchelune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marchelune/32/112334_2.png) [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Post date:** [October 20, 2022, 2:31pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126/1 "2022-10-20T14:31:21Z")

</div>

Hi there!

I'm investigating the best way to monitor API uptime, and I have checked out the synthetics samples.  
A lot of APIs under test require authentication, thus some sort of credentials needs to be available during the test. The section [working with secrets and sensitive values](https://www.elastic.co/guide/en/observability/current/synthetics-params-secrets.html#synthetics-secrets-sensitive) informs on how to provide secrets via Heartbeat's keystore, however there is no guidance when it comes to using the Uptime App directly and its ELK-managed test locations.  
Is it perhaps not possible at all?

---

<div class="post-metadata">

**Author:** ![AndersonQ](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andersonq/32/112214_2.png) [@AndersonQ](https://discuss.elastic.co/u/AndersonQ)\
**Post date:** [October 24, 2022, 1:38pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126/2 "2022-10-24T13:38:14Z")

</div>

Hello @Marchelune,

Uptime App uses Heartbeat "behind the scenes", therefore what is valid for heartbeat is also valid for Uptime App.

If it does not answers your question, I'd ask you to be a bit more specific, ideally provide some reproducible example of what you're trying to monitor with Uptime so I can try to give you a more detailed answer.

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [October 24, 2022, 4:48pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126/3 "2022-10-24T16:48:59Z")

</div>

I apologize @Marchelune , it actually is not possible to use the keystore with the public service. While it does use heartbeat behind the scenes, the means by which it works is different. You can however use the new 'parameters' feature for this purpose for browser monitors.

For lightweight monitors, we do encrypt all fields saved in kibana, including HTTP username / password, headers, etc.

---

<div class="post-metadata">

**Author:** ![Marchelune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marchelune/32/112334_2.png) [@Marchelune](https://discuss.elastic.co/u/Marchelune)\
**Post date:** [November 4, 2022, 5:03pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126/4 "2022-11-04T17:03:55Z")

</div>

Thanks fo the answer!  
I guess one could define very limited test accounts and push credentials as part of the synthetic tests parameters.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 28, 2022, 5:03pm UTC](https://discuss.elastic.co/t/working-with-secrets-and-sensitive-values-with-the-uptime-app/317126/5 "2022-11-28T17:03:58Z")

</div>

This topic was automatically closed 24 days after the last reply. New replies are no longer allowed.
