Add a connection
Choose Add harness, Add provider or Add sandbox, pick the integration and paste the key. Secrets are encrypted on arrival and never shown again. The variants page lists the harnesses and sandboxes you can connect. The first connection for an integration becomes its default. Check it works tests a stored credential without revealing it.From the terminal
add prompts for the secret instead of taking it as a flag, since a flag ends up in shell history and the process list. In a script, pipe it in:
--auth picks the method when an integration accepts more than one. --default makes the new connection the one runs use. Methods that sign in through a browser, such as ChatGPT for Codex, can’t be completed from the terminal, and the command says so.
sphynx connectors remove <id> deletes a connection. A run already holding the credential finishes.
Judges and simulated users
A judge that names aharness runs an agent with that harness connection. A judge declared with provider: "openai" needs an OpenAI model connection instead. Add it under Settings > Models.
A case that states a human needs a model to play them. openai, anthropic, google, xai, moonshotai, deepseek, groq and openrouter all serve the same chat-completions API, so the human runs on whichever you connected first. Provider judges call OpenAI’s responses API, which the others don’t serve, so a case scored by one needs openai.
On a self-hosted deployment, set OPENAI_API_KEY in the server and worker environment instead.
A missing model credential is not a startup error. The judge that needs it fails when a case reaches it, and names what was missing.
A ChatGPT subscription is not an OpenAI API key.
Keep credentials out of eval definitions and fixtures. Runs resolve everything they need from stored connections.
Personal or shared
Organization connections are available to everyone. Personal ones (Only me) are yours alone and take precedence for the same integration, so you can run on your own account without changing what your team uses.Missing, rotated, removed
invalid credential.
Removing a connection leaves past runs readable. Removing a default leaves the integration without one, so set another before your next batch.