> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Storing Credentials Locally

> Store credentials encrypted on the gateway instead of in the central vault, so that the secret never leaves your own network.

Credentials normally sit centrally in your tenant's *Vault*: encrypted in the
browser, usable at every gateway afterwards. For credentials that are not to
leave your own network there is a second route: the vault **on the gateway**
itself. We create such an entry, find it again in the browser and see what sets
it apart from the central route.

<Note>
  The prerequisite is an installed and registered gateway, see
  [Installing and Registering the Gateway](/docs/en/scan/gateway-install).
</Note>

## Creating the entry on the gateway

<Steps>
  <Step title="Open the vault">
    In the desktop application on the gateway host we open the *Vault* tab. It
    can only be operated after the registration.
  </Step>

  <Step title="Set type and name">
    *Add* opens the *New Entry* dialog. Five of the six types are available –
    *Microsoft Identity* only when editing an existing entry. As a name we allow
    only `a-z A-Z 0-9 äöüÄÖÜß _ -`.

    <Warning>
      Type and name can **no longer be changed after creation** – the name is at
      the same time the file name of the encrypted file. To rename an entry or give
      it a different type, we create a new one and delete the old one.
    </Warning>
  </Step>

  <Step title="Fill in the fields and apply">
    Depending on the chosen type the matching fields appear – for
    *User/Password* for instance *User Name:* and *Password:*. *Apply* encrypts
    the entry and saves it.

    <Note>
      The desktop application carries names of its own for the same types: what is
      called *User Account*, *SSH Access* and *Entra ID App* in the browser stands
      here as *User/Password*, *User Name/Password/Private Key* and
      *Microsoft Identity*.
    </Note>
  </Step>
</Steps>

## Finding the entry again in the browser

Under *Scan › Credentials* the new entry appears with the *Storage Location*
*Gateway* – but read-only: the row carries no menu and cannot be clicked. Editing
and deleting stay reserved for the desktop application the entry came about in.

The entry can only be used in jobs that run on exactly this gateway – for every
other gateway and every other job it stays invisible, no matter which type it
carries.

## Deleting

*Delete* in the vault asks back: "Do you really want to delete the vault entry?"
After *Yes* the entry disappears there and in the browser.

<Warning>
  **Deregistering the gateway deletes all of its vault entries in one go** –
  without a confirmation of its own, see
  [Installing and Registering the Gateway](/docs/en/scan/gateway-install#signing-in-and-registering).
  A single entry cannot be restored afterwards.
</Warning>

## What sets the local route apart from the central one

The difference lies in what Docusnap365 gets to see. With a central entry the
encrypted secret leaves the network and sits in the vault of Docusnap365. With a
local entry the encrypted file stays on the gateway; in the cloud there is only
the – itself encrypted – key to it, together with a record without secrets.

| | Central (vault) | Local (gateway) |
| - | - | - |
| Editing and deleting | in the browser | only in the gateway's desktop application |
| Usable at | every gateway of the tenant | this one gateway only |
| Storage mode | *Reusable* or *One-time* | always reusable – *One-time* does not exist here |
| Expiration date | possible, with an advance-warning badge and an entry under *Action Required* | no field for it – no expiry, no warning |
| Types | seven, among them *API Key* | six, without the API key |

<Note>
  If several gateways need the same access, we create the entry on each of them
  individually – a local entry applies only to the gateway it came about on.
</Note>

## What's next

For the day-to-day management of the gateway see
[Managing Gateways](/docs/en/scan/gateway). For assigning credentials while creating
a job see [Creating a Scan Job](/docs/en/scan/create-inventory#credentials).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.