12.1 Asset Types, Per-Robot Assets & External Credential Stores
Key Takeaways
Orchestrator assets come in five types: Text, Bool, Integer, Credential, and Secret; Credential and Secret values are encrypted with AES 256.
An asset can have a global value, specific values per account or per account-machine pair, or both; a specific value wins over the global value.
Get Credential returns the username as a String and the password as a SecureString, which activities such as Type Into accept directly.
External credential stores such as CyberArk, Azure Key Vault, HashiCorp Vault, AWS Secrets Manager, and Google Secret Manager hold Credential secrets; read-only stores require the vault admin to create them.
Rotated vault passwords take effect on the next Get Credential call without changing the process or the asset.
12.1 Asset Types, Per-Robot Assets & External Credential Stores
Core Concept: Orchestrator Assets provide a centralized, secure configuration repository that decouples environment-specific parameters, operational thresholds, and authentication secrets from automation workflow packages. By externalizing variables into Orchestrator, developers ensure that automation packages remain completely invariant across Development, Staging, and Production environments, while sensitive credentials remain encrypted at rest and in transit.
In enterprise automation engineering, hardcoding operational variables or access credentials inside .xaml workflows or unencrypted local configuration files introduces critical security vulnerabilities and administrative overhead. If an enterprise portal URL updates, a database connection string changes, or a service account password rotates under corporate security policy, hardcoded workflows require decompilation, code refactoring, regression testing, and CI/CD redeployment. UiPath Orchestrator Assets solve this architectural challenge by providing centralized, dynamically resolved, and role-governed data objects accessible to robots at runtime via secure API calls.
1. Native Orchestrator Asset Architecture
Orchestrator Assets are folder-scoped entities created and administered through the Orchestrator web console or Orchestrator REST APIs. When a robot executes an asset retrieval activity, it issues an authenticated HTTPS request to the Orchestrator OData endpoint (/odata/Assets), which evaluates the requesting robot's folder permissions and execution identity before returning the requested payload.
+-----------------------------------------------------------------------------------+
| ORCHESTRATOR ASSET TAXONOMY |
| |
| +--------------------+ +--------------------+ +-----------------------------+ |
| | TEXT ASSET | | BOOL ASSET | | INTEGER ASSET | |
| | - System URLs | | - Feature flags | | - Max retry counts | |
| | - File paths | | - Debug toggles | | - Timeout durations (ms) | |
| | - Email recipients | | - Approval switches| | - Batch processing limits | |
| +--------------------+ +--------------------+ +-----------------------------+ |
| |
| +-----------------------------------------------------------------------------+ |
| | CREDENTIAL AND SECRET ASSETS | |
| | - Credential: service account username + password | |
| | - Secret: a single value such as an API key | |
| | - Storage: Internal DB (AES-256) or External Vault (CyberArk, Azure Key) | |
| | - Runtime Output: String (Username) + System.Security.SecureString (Password)| |
| +-----------------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------------+
The Five Asset Types
UiPath Orchestrator supports five asset types: Text, Bool, Integer, Credential, and Secret. Credential and Secret values are encrypted with the AES 256 algorithm, and their values can be hidden from developers who still use them in workflows.
-
Text (
String):- Stores string values; quotation marks are not needed.
- Primarily used for environment-specific base URLs (e.g.,
https://sap.corp.internal/api), shared UNC network directory paths (\\fileserver\automation\invoices), regional notification distribution lists, and regex validation patterns. - Retrieved using the
Get Assetactivity, which returns a standardSystem.String.
-
Bool (
Boolean):- Stores binary
TrueorFalsevalues. - Serves as operational feature flags, conditional branching triggers, and maintenance toggles (e.g.,
EnableDeepDiagnosticLogging,BypassDuplicateInvoiceCheck,PerformDryRunOnly). - Retrieved using
Get Asset, with the output bound to aSystem.Booleanvariable.
- Stores binary
-
Integer (
Int32):- Stores 32-bit signed integers (ranging from -2,147,483,648 to 2,147,483,647).
- Utilized for technical thresholds, SLA timers, polling intervals, and batch volume caps (e.g.,
MaxConsecutiveSystemExceptions = 5,HttpTimeoutMilliseconds = 45000,BatchChunkSize = 250). - Retrieved using
Get Asset, with the output bound to aSystem.Int32variable.
-
Credential (
Credential):- A specialized composite asset type storing an identity pair: a Username (
String) and a Password (SecureString). - Encrypted with AES 256 in Orchestrator, or kept in an external credential store. The username may not exceed 512 characters.
- Retrieved strictly using the
Get Credentialactivity, which outputs the username as a standardStringand the password as aSystem.Security.SecureString.
- A specialized composite asset type storing an identity pair: a Username (
-
Secret:
- Stores a single secret value, such as an API key, encrypted like a Credential.
- Useful when there is no username to pair with the value.
2. Global Assets vs. Per-Robot / Per-User Assets
When defining an asset in Orchestrator, administrators configure its value distribution scope: Global (single value) or Per-Robot / Per-User (granular value overrides).
+-----------------------------------------------------------------------------------+
| ASSET RESOLUTION MECHANICS |
| |
| [Robot Requests Asset] |
| │ |
| ▼ |
| Does a specific override exist |
| for this User / Robot account? |
| / \ |
| YES / \ NO |
| ▼ ▼ |
| [Return Granular Value] [Does a Global / Default |
| (e.g., User-specific Value exist for this asset?] |
| profile or API key) / \ |
| YES / \ NO |
| ▼ ▼ |
| [Return Global] [Get Asset throws |
| (Shared ERP an error] |
| Endpoint) |
+-----------------------------------------------------------------------------------+
Global Assets (Single Value)
A Global Asset provides an identical value to every robot executing within that folder, regardless of which machine, user account, or runtime license is executing the job.
- Ideal Use Cases: Static enterprise endpoints (e.g.,
ERP_Base_URL), organization-wide tax rates, general support mailbox addresses, and standardized framework timeouts. - Behavior: Every robot querying the asset name receives the exact same payload. Updating the global asset in Orchestrator immediately affects all subsequent executions across the entire folder.
Per-Robot / Per-User Assets (Granular Value Overrides)
A Per-Robot Asset (in Modern Folders, scoped per User / Robot Account) defines distinct values assigned to specific execution identities. An optional Global Value can be configured as a default fallback.
- Resolution Logic: When a job running under user identity
CORP\Robot_Finance_01invokesGet Assetfor asset keyInvoiceOutputDirectory:- Orchestrator inspects the asset definition for an explicit override mapped to
CORP\Robot_Finance_01. - If an override is found, Orchestrator returns that specific value (e.g.,
D:\LocalCache\Robot01\Out\). - If no specific override is defined for that user, Orchestrator inspects whether a default Global Value is configured. If present, it returns the global default (e.g.,
\\nas\automation\invoices\). - If neither a specific value nor a global value exists for the requesting identity, the Get Asset activity throws an error. Values can be defined per account or per account-machine pair.
- Orchestrator inspects the asset definition for an explicit override mapped to
Real-World Enterprise Scenarios for Per-User Assets
| Scenario | Asset Type | Implementation Architecture |
|---|---|---|
| Dedicated ERP User Logins | Credential | Each robot in a pool possesses its own named ERP service account (ERP_USR_BOT1, ERP_USR_BOT2) to maintain individual application audit trails. A single asset name ERP_App_Credentials returns the correct identity based on the executing robot account. |
| Regional Tax Engine Keys | Text | Robots executing in different geographical regions require distinct API authorization tokens. The asset TaxEngine_ApiKey returns the UK API key for UK runners and the US API key for US runners. |
| Local Scratch Directories | Text | High-throughput unattended robots processing large image files require local disk caching (C:\Scratch\Bot01 vs D:\FastNVMe\Bot02) to eliminate network storage bottlenecks. |
3. Secure Credential Management & The Get Credential Activity
Securing authentication credentials represents a cornerstone of enterprise RPA compliance. Storing plaintext passwords inside workflows, project arguments, or Data\Config.xlsx sheets violates regulatory frameworks including Sarbanes-Oxley (SOX), HIPAA, and PCI-DSS.
The Get Credential Activity Workflow
The Get Credential activity (contained within UiPath.System.Activities) retrieves an encrypted credential asset from Orchestrator:
' Conceptual invocation of Get Credential in UiPath Studio
GetCredential(
FolderPath := "Finance/AccountsPayable",
CredentialName := "SAP_ServiceAccount",
out_Username := str_Username, ' Type: System.String
out_Password := sec_Password ' Type: System.Security.SecureString
)
Deep Dive: System.Security.SecureString Mechanics
Why does UiPath output the password as a System.Security.SecureString rather than a standard System.String?
- Limited Exposure: A standard
.NETSystem.Stringis immutable and stays in managed memory until the garbage collector reclaims it, so a plaintext password can linger in memory dumps and crash logs.System.Security.SecureStringkeeps the characters out of ordinary strings and, on Windows, stores them encrypted. - Clearing on Dispose: When the
SecureStringobject is disposed, its buffer is cleared. - UI Integration:
Type Intoacceptssec_Passwordin its Secure text field, so the workflow never needs to create a plaintext copy of the password.
String versus SecureString
String: plaintext stays in managed memory until garbage collection
and can show up in memory dumps or logs
SecureString: characters kept outside ordinary strings (encrypted on Windows);
passed straight to Type Into's Secure Text field,
so the workflow never holds a plaintext copy
Caution
Avoid Plaintext Conversion Anti-Patterns: Converting a SecureString to a plaintext String (e.g., using new System.Net.NetworkCredential(string.Empty, sec_Password).Password) completely circumvents its security architecture. Plaintext extraction should never be performed unless interacting with legacy REST libraries that strictly lack SecureString overloads.
4. Enterprise External Credential Stores
While the internal Orchestrator database provides robust AES-256 encryption for credentials, large enterprises frequently mandate that all machine identities, database passwords, and service account keys reside within a dedicated enterprise Privileged Access Management (PAM) vault.
UiPath Orchestrator supports direct integration with External Credential Stores, decoupling secret storage entirely from the Orchestrator SQL database.
+-----------------------------------------------------------------------------------+
| EXTERNAL CREDENTIAL STORE ARCHITECTURE |
| |
| +---------------------+ |
| | UiPath Robot | |
| | (Execution Agent) | |
| +----------┬----------+ |
| │ 1. Invokes Get Credential ("SAP_Vault_Asset") |
| ▼ |
| +---------------------+ 2. Resolves Asset Definition |
| | UiPath Orchestrator | ──────────────────────────────────────────┐ |
| | (API & Gateway) | │ |
| +----------▲----------+ ▼ |
| │ +--------------------+ |
| │ 4. Returns the secret to the | Credential Store: | |
| │ robot over its encrypted connection | External Vault Ref | |
| │ +---------┬----------+ |
| │ │ |
| │ 3. Authenticates via mTLS / AppID │ |
| │ and queries Secret Identifier │ |
| │ ▼ |
| +----------┴------------------------------------------------------------------+ |
| | ENTERPRISE CREDENTIAL VAULT | |
| | |
| | [CyberArk Enterprise Password Vault] / [Azure Key Vault] |
| | [HashiCorp Vault (KV Engine)] / [AWS Secrets Manager] |
| +-----------------------------------------------------------------------------+ |
+-----------------------------------------------------------------------------------+
Supported External Credential Store Platforms
-
CyberArk Enterprise Password Vault:
- Connects via CyberArk Central Credential Provider (CCP) or Application Identity Manager (AIM).
- Configuration requires: Web Service URL, Application ID (
AppID), Safe name, Folder, and Object name. - Orchestrator authenticates to CyberArk using client certificates (mTLS) or authorized IP address whitelisting.
-
Azure Key Vault:
- Connects via Microsoft Entra ID (Azure AD) service principals or Azure Managed Identities.
- Configuration requires: Vault URI (
https://<vault-name>.vault.azure.net/), Directory (Tenant) ID, Application (Client) ID, and Client Secret or X.509 Certificate.
-
HashiCorp Vault:
- Integrates using AppRole authentication or token-based authentication with Vault's Key-Value (KV) secrets engine (v1 and v2).
- Configuration requires: Vault URL, Engine Path, Role ID, and Secret ID.
-
AWS Secrets Manager:
- Connects with AWS Identity and Access Management (IAM) access keys.
- Configuration requires: AWS Region, Secret Name/ARN, Access Key ID, and Secret Access Key.
-
Other stores: Orchestrator's credential store list also includes BeyondTrust, Delinea (Thycotic) Secret Server, and Google Secret Manager. Several integrations are read only: the vault administrator creates the secrets, and Orchestrator only reads them by their external names. External stores apply to Credential assets; Text, Bool, and Integer values stay in Orchestrator.
Runtime Resolution Flow
When an asset is backed by an External Credential Store, Orchestrator does not store the secret password in its database. Instead, Orchestrator stores only the metadata pointer (e.g., CyberArk Safe + Object name, or Azure Key Vault Secret Identifier):
- The Robot executes
Get Credentialand requests the asset from Orchestrator. - Orchestrator looks up the asset record, recognizes that it is assigned to an external credential store, and identifies the target vault reference.
- Orchestrator establishes an outbound connection to the external vault using its enterprise service credentials.
- The external vault verifies Orchestrator's identity, evaluates vault access control policies, and returns the current secret payload.
- Orchestrator returns the secret to the requesting robot over its encrypted connection. For vaults inside the corporate network, the Orchestrator Credentials Proxy lets a cloud Orchestrator reach them without exposing the vault to the internet.
5. Credential Rotation & Audit Logging
Integrating an external vault raises one main operational question: how to handle automated password rotation without interrupting running automations.
Password Rotation
Because the secret lives in the vault, a PAM rotation takes effect on the next Get Credential call without changing the process or the asset:
- The vault rotates the service account password and updates the target application.
- The next Get Credential request makes Orchestrator read the current secret from the vault.
- The robot logs in with the new password; no package, asset, or configuration file changes.
A job that is already logged in keeps its session, so plan rotations outside critical processing windows or make the login workflow retry once with a freshly fetched credential.
Audit Trails
- Orchestrator: the Audit page records who created, changed, or deleted assets, credential stores, and other entities, and job logs show which process ran under which account.
- Vault: the external vault keeps its own record of every secret that Orchestrator's identity read.
- Together, the two trails show who can change a credential, when the vault handed it out, and which job used it.
6. Architecture Comparison & Security Best Practices
| Architectural Attribute | Internal Orchestrator Database | External Credential Store (CyberArk / Azure Key) |
|---|---|---|
| Secret Storage Location | Encrypted within Orchestrator SQL Server | Stored exclusively inside external enterprise vault |
| Encryption Standard | AES 256 in Orchestrator | Whatever the enterprise vault provides |
| Password Rotation | Manual update via Orchestrator UI or API | Automated rotation driven by corporate PAM policies |
| Operational Overhead | Low; zero external infrastructure dependencies | Moderate; requires vault provisioning and network peering |
| Network Dependency | None beyond Orchestrator | The vault must be reachable (directly or through the Credentials Proxy) |
| Typical Choice | Most automations | Organizations whose security policy requires every secret to live in a central PAM vault |
Security Best Practices for Orchestrator Assets
- Enforce Least Privilege RBAC: Grant Assets View only to the accounts that need to read assets; credential assets use the same Assets permissions. Do not give robot roles Assets Create, Edit, or Delete.
- Never Pass Secrets as Plaintext Arguments: In modular workflows, pass credentials between
.xamlfiles strictly asSystem.Security.SecureStringvariables. Never serialize credentials into JSON logs or queue itemSpecificContent. - Folder Isolation for Sensitive Assets: Keep sensitive HR, payroll, and payment assets in a folder branch where only the authorized people and robot accounts are assigned; inherited access cannot be removed in a subfolder.
- Watch for Failures: Alert on jobs that fault at login or on repeated
Get Credentialerrors, which often signal an expired or rotated password.
A developer configures an asset named 'InvoiceTaxRate' in a Modern Folder with a Global Value of 0.08. An override value of 0.05 is specifically assigned to the user account 'CORP\Bot_Finance'. When an unattended job runs under 'CORP\Bot_Finance' and calls Get Asset for 'InvoiceTaxRate', what value is returned?
0.08, because global values always take precedence over user-specific overrides.
0.05, because Orchestrator resolves specific user account overrides before falling back to the global value.
0.13, because Orchestrator aggregates the global value and user override.
An exception is thrown because assets cannot have both a global value and a user override simultaneously.
Why does the Get Credential activity return the password as a System.Security.SecureString rather than a standard System.String?
SecureString automatically translates password characters into localized language encodings.
Standard strings cannot exceed 16 characters in UiPath Studio workflows.
SecureString bypasses the Windows operating system message queue to accelerate execution speed.
SecureString keeps the password out of ordinary strings (stored encrypted on Windows), which reduces exposure in memory dumps and logs.
When UiPath Orchestrator is integrated with an External Credential Store such as CyberArk or Azure Key Vault, where is the sensitive password secret physically stored?
Exclusively inside the external enterprise vault; Orchestrator stores only the vault reference metadata and fetches the secret at runtime.
In both the Orchestrator SQL database and the external vault via continuous two-way database replication.
Compiled directly into the robot's local NuGet project package during publishing from Studio.
In an unencrypted local XML cache on the host machine executing the robot process.
Sections you finish are checked off in the contents.