Secrets
secrets: - name: GITHUB_TOKEN source: secret-manager scope: - githubmcpServers: - name: github transport: streamable-http url: https://mcp.example.com/github auth: secretRef: GITHUB_TOKEN- A
secretRefmust name a declared secret whosescopeincludes the consumer. - Manifests with fields such as
token,passwordorapiKeyholding literal values are rejected. - Runtimes must not pass secret values to models and must not write them to audit events, logs or approval requests.
Normative text: Secrets.