megachangelog
Security

Secure Marketplace credentials with Production-only access

Integration resources can now be restricted to Production-only environments, protecting sensitive credentials from being readable in the dashboard or CLI. This security setting requires Owner permissions to revert and disconnects any non-production environment connections.

You can now secure native integration resources by restricting where they can be used. Setting a resource to removes non-production access and protects credentials as . This makes it so secret values or no longer readable from the dashboard or CLI Production onlysensitive environment variables

From the integration resource , select and save. We recommend that you rotate the secrets of the integration resource after saving.SettingsAllowed Environments → Production only

Once applied:

Reverting this setting requires for your Vercel team. Owners can re-enable Development and Preview environment from Settings and reconnect projects if needed. You may be prompted to reauthenticate with an MFA challenge depending on your settings. Learn more in the Vercel .Owner permissions documentation

Read more

  • Development and Preview connections are removed

  • New non-production connections are blocked

  • Connections without a Production target are disconnected

  • Credentials are protected and no longer readable

securitymarketplaceintegrationscredentialsaccess-control

Source: original entry ↗