# Maintain tools and credentials

Update a connection whenever its external credentials, permissions, or service address change.

## Rotate credentials or edit an instance

1. Find the target tool in the library.
2. For search tools, use the key/token replacement action. For instance-based tools, edit the target instance.
3. Enter the new parameters and save.
4. Reopen configuration to confirm the update. Do not expect sensitive fields to display complete plaintext values.
5. Test the connection, then run a small task that genuinely requires the capability.

Several forms offer a timeout setting with a default of 30 seconds and a maximum of 300 seconds. Increase it only for slow responses. Fix credentials or permissions for authentication and authorization errors.

## Disconnect or delete

Search tools provide a credential-deletion action. Instance-based tools provide disconnect or delete actions as available on the page. Check dependent agents and tasks first, perform the intended operation, then inspect the list status.

## Enter credentials in the correct fields

Put API keys, tokens, authorization codes, and private keys in their sensitive configuration fields, not prompts, screenshots, or descriptions. Mailboxes commonly require a client authorization code rather than the account login password. See the [configuration guides](configuration/index.md) for tool-specific requirements.
