IMS Documentation
IMS Build 9.4.4.0 technical baseline

Secret Vault

How IMS keeps sensitive database and integration credentials behind the server-side API boundary and exposes only the runtime values needed by authorized components.

Purpose

IMS uses a central protected secret store for credentials that should not be distributed as reusable plaintext application configuration. Access to those values is mediated by IMS.Api and tied to the requesting user/session, workstation, company/module/resource and intended secret.

Company database passwords

The IMS Global Companies screen can register/change a company database password, but an existing saved password is not displayed back in the form. During new database provisioning, IMS Global uses the password supplied for the new database and, after successful creation/validation, stores the secret through IMS.Api.

Operational rule

Do not bypass the vaultDocumentation and integrations should use the approved IMS secret flow rather than copying database/service passwords into user guides, scripts or workstation configuration.