Any node that connects to an external system - such as Microsoft 365, a database, or a third-party service - needs a credential to authenticate. Credentials store the details required to make that connection, so you only need to set them up once.
This article explains how to add, use, share, update, and delete credentials, and how to set up Microsoft 365 connections.
Where credentials live
Open Credentials in the left-hand sidebar of Evo Workflow Automation. The page lists your own credentials and any that have been shared with you.
Each credential has three parts.
A name - choose something descriptive so you can identify it easily.
A type - for example, API Key, Basic Auth, or Microsoft Outlook OAuth2.
A secret payload - the actual key, token, or connection string. Sensitive values are masked once saved.
Credentials are private by default. Sharing is opt-in, per credential, to named users or whole teams.
Supported credential types
The full list of credential types is available in the New credential dialogue. The main categories are listed below.
Category | Types |
General | API Key, Basic Auth, Bearer Token, Header Auth, JWT |
AI | OpenAI, Anthropic Claude, Azure OpenAI, Google Gemini, Groq |
Microsoft 365 | Outlook, Teams, SharePoint, OneDrive, Entra ID |
Databases | SQL Server, MySQL, PostgreSQL, MongoDB, Redis, Elasticsearch |
Cloud storage | Azure Blob Storage, AWS, GCP |
SMTP, SendGrid | |
Access products | Donorfy, Data Engine API |
Productivity | Asana, Stripe, GitHub, Slack, Discord, Telegram |
📌 Note: This list covers the main categories. Open the New credential dialogue in Evo Workflow Automation to see the full list available in your environment.
Add a credential
Open Credentials in the sidebar.
Select New credential.
Choose the credential type. The form updates to show the fields required for that type.
Complete the fields. Sensitive values are masked as you type.
Select Save.
The credential is now available to select in any node that supports its type.
🤓 Tip: If the credential form includes a Test connection button, use it before saving. A credential that fails the test will fail every workflow that uses it — it is easier to catch the problem here than to trace it through workflow executions later.
Use a credential in a node
Open any integration node's configuration panel. The Credential dropdown near the top lists every credential you own and every credential shared with you, filtered to those that match the node's type.
Evo Workflow Automation remembers the last-used credential per type and sets it as the default. If you only have one Microsoft Outlook credential, for example, Outlook nodes will select it automatically.
Evo Connector and Evo Tool nodes
Evo Connector and Evo Tool nodes work differently from other integration nodes. They authenticate automatically using your Evo identity — no stored credential is required.
What you do configure on these nodes is which connector to call. For connectors that work with a multi-instance application — for example, a product with more than one company database — you also need to select which instance to connect to.
Open the node's configuration panel and select a connector from the catalogue dropdown.
If the connector requires an instance, an instance picker appears. Select the correct instance before configuring the rest of the node.
Save the workflow. The selected instance is stored on the node and used for every run of that workflow.
If the connector does not require an instance, the picker does not appear and there is nothing extra to configure.
Share a credential
Sharing a credential means one person holds the secret and the rest of the team can use it in their workflows without ever seeing the underlying value.
Open the credential.
Select the Sharing tab.
Add users by name, or add an entire team.
Select Save.
Recipients can use the credential in their workflows immediately. Sharing grants execution access only - recipients cannot read the secret value back out.
⚠️ Important: Share credentials at the smallest level that gets the job done — usually a team, sometimes named individuals. A shared production database connection or a shared Microsoft account carries real risk if a team member's account is compromised.
How credential access is resolved
When a workflow runs, Evo Workflow Automation checks the following in order to decide whether the workflow can use a given credential.
Ownership — the credential's owner is running the workflow.
Direct share — the credential has been shared with the workflow owner as an individual.
Team share — the credential has been shared with a team the workflow owner belongs to.
Workflow context — the workflow is already linked to the credential.
Share link — temporary execution-only access via a workflow share link.
System credentials — credentials managed by Access that are available to all users automatically, such as the Access Mail service.
If none of these conditions are met, the node fails with an authorisation error.
📌 Note: Workflows always run as the workflow owner, regardless of who triggers them. If the workflow owner does not have access to a required credential, the workflow will fail even if the person who triggered it does.
Set up a Microsoft 365 connection
Microsoft 365 integrations — Outlook, Teams, SharePoint, OneDrive, and Entra ID — connect through the Microsoft Graph API. Before you can use these nodes, your organisation's IT team needs to complete a one-time Azure app registration on your Microsoft tenant.
This setup is done once per tenant. Once complete, anyone in the organisation can create a Microsoft credential and use it in their workflows.
Step 1: raise a request with your IT team
Ask your IT team to set up an Azure app registration for Evo Workflow Automation. Let them know which Microsoft services you need to connect to, as each service requires specific permissions.
Service | Permissions required |
Microsoft Outlook | Mail.Read, Mail.Send, Mail.ReadWrite |
Microsoft Teams | ChannelMessage.Read.All, ChannelMessage.Send, Chat.ReadWrite |
Microsoft SharePoint | Sites.Read.All, Sites.ReadWrite.All |
Microsoft OneDrive | Files.Read.All, Files.ReadWrite.All |
Microsoft Entra ID | User.Read.All, Group.Read.All |
Step 2: receive your connection details
When your IT team completes the setup, they will provide three values.
Tenant ID — your organisation's Microsoft tenant identifier.
Client ID — the app registration's identifier.
Client Secret — the secret used to authenticate the connection.
Treat the Client Secret like any other sensitive credential — do not share it in chat or store it in a shared document.
Step 3: create the credential
Open Credentials in the sidebar.
Select New credential and choose the Microsoft service type — for example, Microsoft Outlook OAuth2.
Enter the Tenant ID, Client ID, and Client Secret provided by your IT team.
Select Authorise. A Microsoft consent screen opens — sign in with the account you want the workflow to act as and grant consent.
The credential page shows the connection as Authorised once complete.
Select Save.
Step 4: use the credential in a workflow
Add the corresponding node to your workflow canvas — for example, a Microsoft Outlook node — and select the credential you created from the dropdown. The node is now ready to use.
📌 Note: Each Microsoft service requires its own credential. If you need to connect to both Outlook and Teams, add two separate credentials — one for each service.
Update or rotate a credential
Open Credentials in the sidebar.
Select the credential you want to update.
Update the relevant fields. The masked secret stays masked — entering new text overwrites the existing value; leaving the mask in place keeps it unchanged.
Select Save.
Workflows that use the credential pick up the new value on their next execution. You do not need to re-select the credential in every node.
For OAuth2 credentials, re-authorisation is sometimes required when the token expires or the provider revokes consent. Open the credential and select Authorise to go through the consent screen again.
Delete a credential
Open Credentials in the sidebar.
Open the credential.
Select Delete.
⚠️ Important: Any workflow that references a deleted credential will fail on its next execution with a "credential not found" error. Update those workflows to use a different credential, or delete them if they are no longer needed.
Import and export credentials
The Credentials page supports bulk import and export. Exported credentials include the secret payloads in an encrypted format — the export file is not human-readable, but importing it on the same platform restores all credentials intact.
Use import and export when:
You are setting up a new organisation from an existing one.
You want to clean up local or development credentials before sharing a workflow with your team.
Common issues
Issue | What to check |
A node fails with a "credential not authorised" error. | Check that the credential has been shared with the workflow owner, or that the workflow owner created the credential themselves. |
A Microsoft node fails to authenticate. | Open the credential and select Authorise to complete the Microsoft consent screen. Check that the Azure app registration has been completed and the correct permissions granted. |
An OAuth2 credential stops working. | Open the credential and select Authorise to re-authorise the connection. |
A webhook node rejects incoming requests. | Check that the authentication mode set on the Webhook trigger matches the method used by the sending service. |
You need different Microsoft permission scopes for different workflows. | Create a second credential with a different name and select the correct one on each node. |
