---
title: Keys and certificates
slug: keys-and-certificates
description: Add and manage keys and certificates for secure authentication and data protection
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/7cHyi9JnHEeIy6oHajXii_domino-zoomin-purple-a-1.png
docTags: 
createdAt: 2025-02-03T13:29:13.656Z
---

Some apps in Make require you to use private or public keys or certificates for secure authentication and data protection. You have to add them in the Scenario Builder in the module settings of the app that requires a key or a certificate.&#x20;

## Keys and keychains

Keys are used by the [Encryptor](docId\:wUWoc-qtjewGHpYkXY9Zb) app in its AES Encrypt (advanced), AES Decrypt (advanced), Create digital signature, Decrypt a PGP message, and Encrypt a PGP message modules.

The [SSH](https://apps.make.com/ssh) app also allows using private keys to create the connection.&#x20;

Although a different type of key, the [HTTP](https://apps.make.com/http) app also saves the credentials you provide for making an HTTP request as a keychain for the API key and Basic Auth authentication types.

### Add a key&#x20;

You should add the keys in the module settings when an app's module requires a public or private key.&#x20;

Let's take the **Encryptor > AES Encrypt (advanced)** module as an example. To add a key there, you will:

::::WorkflowBlock
:::WorkflowBlockItem
Create a new scenario or open an existing one.
:::

:::WorkflowBlockItem
Add the **Encryptor > AES Encrypt (advanced)** module.&#x20;
:::

:::WorkflowBlockItem
In the **Key** field, click **Create a keychain**.&#x20;
:::

:::WorkflowBlockItem
In the **Add new keychain** window, enter your key and other details and click **Create**.

::Image[]{src="https://app.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/0hXykH-85QS6m7BEi03w3-20251202-095309.png" size="60" width="1572" height="1218" position="center" showCaption="false"}
:::
::::

Once you create it and save the module settings, the key is saved in the **Keys** section. There, you can manage all the created keys.

### Edit or delete a key

To edit a key:

::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Credentials**, and switch to **Keys.**﻿

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/fiD5I5lPGREgAOLw8p7tq-20260210-123211.png" size="50" width="1208" height="946" position="center" showCaption="false"}
:::

:::WorkflowBlockItem
Click the **three dots > Edit&#x20;**&#x6E;ext to the required key or keychain.

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/aauSHM18954HHi65JHPKt-20251202-103019.png)
:::

:::WorkflowBlockItem
You will see a form where you can edit the key and its details. Once you make the edits, click **Save**.

::Image[]{src="https://app.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/tG34dgn3X83gDukKgFdg4-20251202-101252.png" size="40" width="774" height="630" position="center" showCaption="false"}
:::
::::

Make applies the saved changes immediately. After confirming, the key is updated in all the modules where it's used.

To delete a key:

:::::WorkflowBlock
:::WorkflowBlockItem
In the left sidebar, click **Credentials**, and switch to **Keys.**﻿
:::

:::WorkflowBlockItem
Click the **three dots > Delete&#x20;**&#x6E;ext to the required key or keychain.

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/uVefhQk4BavSjYWBRbX70-20251202-103518.png)
:::

::::WorkflowBlockItem
In a pop-up window, click **Delete** to confirm.

:::hint{type="info"}
If the key is used in scenario(s), a warning will appear showing the scenario name(s). Click **OK** to confirm the deletion.
:::

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/EfA9PGmNS4kxg2lAZpXoL-20251218-092615.png" size="40" width="790" height="414" position="center" showCaption="false"}
::::
:::::

After confirming, the key is deleted from all the modules where it's used.

## Certificates

You may use certificates in the SSH app and for [configuring SSO](https://help.make.com/google-saml#7h2Hk) in Make.&#x20;

### Add a certificate

Let's take the **SSH > Execute a command** module as an example. To add a certificate there, you will:

::::WorkflowBlock
:::WorkflowBlockItem
Create a new scenario or open an existing one.
:::

:::WorkflowBlockItem
Add the **SSH > Execute a command** module.&#x20;
:::

:::WorkflowBlockItem
For a certificate:

1. In the **Connection** field, click **Create a connection**.&#x20;
2. In the **Auth type** field of the next window, select **Username** **and key**.&#x20;
3. In the **Private** **key** field, click **Extract**.
4. In the **Extract** field, choose **Certificate**.&#x20;

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/LcQB-ID2242bd5HZFAkoc-20251203-090444.png)
:::

:::WorkflowBlockItem
Upload the certificate, add the **Password,** and click **Save**.
:::

:::WorkflowBlockItem
Then configure all the module fields.&#x20;
:::
::::

## Ways of inserting keys and certificates

There are two ways of inserting a key or certificate:

- Direct insert
- Extract from the file (P12, PFX or PEM)&#x20;

### Direct insert

With a direct insert, you just copy the key and paste it into the required field. For example, for **RSA PRIVATE KEY&#x20;**&#x69;n the **SSH > Execute a command** module:

::Image[****]{src="https://app.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/TnHpxcVoEQBdtdUwd_dmd-20251203-090101.png" size="40" width="700" height="902" position="center" showCaption="false"}

:::hint{type="info"}
OPENSSH PRIVATE KEY is not supported. This has to be converted using the following command in Terminal: `ssh-keygen -p -m PEM -f <pathToTheKey>`. For Windows, you can use the PuTTy key generator.
:::

### Extract from the file (P12, PFX or PEM)&#x20;

To extract a Private Key or a Certificate, you need to use the key extraction function. This will also allow you to extract the key from encrypted files.

The supported file formats are **P12**, **PFX**, and **PEM**.&#x20;

Let's take the **SSH > Execute a command** module as an example. To extract a Private Key or a Certificate, you will:

:::::WorkflowBlock
:::WorkflowBlockItem
Create a new scenario or open an existing one.
:::

:::WorkflowBlockItem
Add the **SSH > Execute a command** module.&#x20;
:::

:::WorkflowBlockItem
In the **Connection** field, click **Create a connection**.&#x20;
:::

:::WorkflowBlockItem
In the **Auth type** field of the next window, select **Username** **and key**.&#x20;
:::

:::WorkflowBlockItem
In the **Private** **key** field, click **Extract**.
:::

:::WorkflowBlockItem
In the **Extract** field, choos&#x65;**&#x20;Private key.&#x20;**
:::

:::WorkflowBlockItem
Click the **Choose File** button.

::Image[]{src="https://app.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/ykb9A_KZPWTm7-kC1rcCe-20251203-092720.png" size="70" width="1408" height="1082" position="center" showCaption="false"}
:::

::::WorkflowBlockItem
Browse and **Open** the required file. For example, when you create a Linux Based EC2 instance on AWS, you receive the login credentials in the PEM file:

:::BlockQuote
\[username\@hostname aws]$ ls&#x20;
IMTExample.pem&#x20;
\[username\@hostname aws]$
:::

The file contains the private key that is used to connect to the instance.

:::BlockQuote
\[username\@hostname aws]$ vat IMTExample.pem&#x20;
\-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAz7F3k1q2x9K8JfN8u1wPp8Yk4Q2Lw3mA9bR1q2zZ+/QeR9Lh
J3Kf4wQb7vR9kP2n4x1pQ2XhQ9L0vQj3F8tUzZxPnG1kZ0lMnU8BtR5KJ
.........................................................
4sZt3JmU7YwP8Qj3mNqP9jLw2yZk8NwQvH2Rr0YpM5Xk3tPw8mXl0QxNr0aY9uTn
\-----END RSA PRIVATE KEY-----
:::

This is a private key you will extract from a PEM file.
::::

:::WorkflowBlockItem
Once you extract the file, enter the password in the respective field, if needed.
:::

:::WorkflowBlockItem
Click **Save**.
:::
:::::

The private key will be exported from your file and will be used to connect to the required service.
