12.1 Asset Types, Per-Robot Assets & External Credential Stores

Key Takeaways

  • Orchestrator assets come in five types: Text, Bool, Integer, Credential, and Secret; Credential and Secret values are encrypted with AES 256.

  • An asset can have a global value, specific values per account or per account-machine pair, or both; a specific value wins over the global value.

  • Get Credential returns the username as a String and the password as a SecureString, which activities such as Type Into accept directly.

  • External credential stores such as CyberArk, Azure Key Vault, HashiCorp Vault, AWS Secrets Manager, and Google Secret Manager hold Credential secrets; read-only stores require the vault admin to create them.

  • Rotated vault passwords take effect on the next Get Credential call without changing the process or the asset.

Last updated: September 2026

12.1 Asset Types, Per-Robot Assets & External Credential Stores

Core Concept: Orchestrator Assets provide a centralized, secure configuration repository that decouples environment-specific parameters, operational thresholds, and authentication secrets from automation workflow packages. By externalizing variables into Orchestrator, developers ensure that automation packages remain completely invariant across Development, Staging, and Production environments, while sensitive credentials remain encrypted at rest and in transit.

In enterprise automation engineering, hardcoding operational variables or access credentials inside .xaml workflows or unencrypted local configuration files introduces critical security vulnerabilities and administrative overhead. If an enterprise portal URL updates, a database connection string changes, or a service account password rotates under corporate security policy, hardcoded workflows require decompilation, code refactoring, regression testing, and CI/CD redeployment. UiPath Orchestrator Assets solve this architectural challenge by providing centralized, dynamically resolved, and role-governed data objects accessible to robots at runtime via secure API calls.


1. Native Orchestrator Asset Architecture

Orchestrator Assets are folder-scoped entities created and administered through the Orchestrator web console or Orchestrator REST APIs. When a robot executes an asset retrieval activity, it issues an authenticated HTTPS request to the Orchestrator OData endpoint (/odata/Assets), which evaluates the requesting robot's folder permissions and execution identity before returning the requested payload.

+-----------------------------------------------------------------------------------+
|                         ORCHESTRATOR ASSET TAXONOMY                               |
|                                                                                   |
|  +--------------------+  +--------------------+  +-----------------------------+  |
|  |     TEXT ASSET     |  |     BOOL ASSET     |  |        INTEGER ASSET        |  |
|  | - System URLs      |  | - Feature flags    |  | - Max retry counts          |  |
|  | - File paths       |  | - Debug toggles    |  | - Timeout durations (ms)    |  |
|  | - Email recipients |  | - Approval switches|  | - Batch processing limits   |  |
|  +--------------------+  +--------------------+  +-----------------------------+  |
|                                                                                   |
|  +-----------------------------------------------------------------------------+  |
|  |                         CREDENTIAL AND SECRET ASSETS                        |  |
|  | - Credential: service account username + password                           |  |
|  | - Secret: a single value such as an API key                                 |  |
|  | - Storage: Internal DB (AES-256) or External Vault (CyberArk, Azure Key)    |  |
|  | - Runtime Output: String (Username) + System.Security.SecureString (Password)|  |
|  +-----------------------------------------------------------------------------+  |
+-----------------------------------------------------------------------------------+

The Five Asset Types

UiPath Orchestrator supports five asset types: Text, Bool, Integer, Credential, and Secret. Credential and Secret values are encrypted with the AES 256 algorithm, and their values can be hidden from developers who still use them in workflows.

  1. Text (String):

    • Stores string values; quotation marks are not needed.
    • Primarily used for environment-specific base URLs (e.g., https://sap.corp.internal/api), shared UNC network directory paths (\\fileserver\automation\invoices), regional notification distribution lists, and regex validation patterns.
    • Retrieved using the Get Asset activity, which returns a standard System.String.
  2. Bool (Boolean):

    • Stores binary True or False values.
    • Serves as operational feature flags, conditional branching triggers, and maintenance toggles (e.g., EnableDeepDiagnosticLogging, BypassDuplicateInvoiceCheck, PerformDryRunOnly).
    • Retrieved using Get Asset, with the output bound to a System.Boolean variable.
  3. Integer (Int32):

    • Stores 32-bit signed integers (ranging from -2,147,483,648 to 2,147,483,647).
    • Utilized for technical thresholds, SLA timers, polling intervals, and batch volume caps (e.g., MaxConsecutiveSystemExceptions = 5, HttpTimeoutMilliseconds = 45000, BatchChunkSize = 250).
    • Retrieved using Get Asset, with the output bound to a System.Int32 variable.
  4. Credential (Credential):

    • A specialized composite asset type storing an identity pair: a Username (String) and a Password (SecureString).
    • Encrypted with AES 256 in Orchestrator, or kept in an external credential store. The username may not exceed 512 characters.
    • Retrieved strictly using the Get Credential activity, which outputs the username as a standard String and the password as a System.Security.SecureString.
  5. Secret:

    • Stores a single secret value, such as an API key, encrypted like a Credential.
    • Useful when there is no username to pair with the value.

2. Global Assets vs. Per-Robot / Per-User Assets

When defining an asset in Orchestrator, administrators configure its value distribution scope: Global (single value) or Per-Robot / Per-User (granular value overrides).

+-----------------------------------------------------------------------------------+
|                         ASSET RESOLUTION MECHANICS                                |
|                                                                                   |
|                               [Robot Requests Asset]                              |
|                                          │                                        |
|                                          ▼                                        |
|                         Does a specific override exist                            |
|                         for this User / Robot account?                            |
|                                  /               \                                |
|                            YES  /                 \  NO                           |
|                                ▼                   ▼                              |
|                    [Return Granular Value]   [Does a Global / Default             |
|                     (e.g., User-specific      Value exist for this asset?]        |
|                      profile or API key)              /        \                  |
|                                                 YES  /          \  NO             |
|                                                     ▼            ▼                |
|                                             [Return Global]  [Get Asset throws    |
|                                              (Shared ERP       an error]          |
|                                               Endpoint)                           |
+-----------------------------------------------------------------------------------+

Global Assets (Single Value)

A Global Asset provides an identical value to every robot executing within that folder, regardless of which machine, user account, or runtime license is executing the job.

  • Ideal Use Cases: Static enterprise endpoints (e.g., ERP_Base_URL), organization-wide tax rates, general support mailbox addresses, and standardized framework timeouts.
  • Behavior: Every robot querying the asset name receives the exact same payload. Updating the global asset in Orchestrator immediately affects all subsequent executions across the entire folder.

Per-Robot / Per-User Assets (Granular Value Overrides)

A Per-Robot Asset (in Modern Folders, scoped per User / Robot Account) defines distinct values assigned to specific execution identities. An optional Global Value can be configured as a default fallback.

  • Resolution Logic: When a job running under user identity CORP\Robot_Finance_01 invokes Get Asset for asset key InvoiceOutputDirectory:
    1. Orchestrator inspects the asset definition for an explicit override mapped to CORP\Robot_Finance_01.
    2. If an override is found, Orchestrator returns that specific value (e.g., D:\LocalCache\Robot01\Out\).
    3. If no specific override is defined for that user, Orchestrator inspects whether a default Global Value is configured. If present, it returns the global default (e.g., \\nas\automation\invoices\).
    4. If neither a specific value nor a global value exists for the requesting identity, the Get Asset activity throws an error. Values can be defined per account or per account-machine pair.

Real-World Enterprise Scenarios for Per-User Assets

ScenarioAsset TypeImplementation Architecture
Dedicated ERP User LoginsCredentialEach robot in a pool possesses its own named ERP service account (ERP_USR_BOT1, ERP_USR_BOT2) to maintain individual application audit trails. A single asset name ERP_App_Credentials returns the correct identity based on the executing robot account.
Regional Tax Engine KeysTextRobots executing in different geographical regions require distinct API authorization tokens. The asset TaxEngine_ApiKey returns the UK API key for UK runners and the US API key for US runners.
Local Scratch DirectoriesTextHigh-throughput unattended robots processing large image files require local disk caching (C:\Scratch\Bot01 vs D:\FastNVMe\Bot02) to eliminate network storage bottlenecks.

3. Secure Credential Management & The Get Credential Activity

Securing authentication credentials represents a cornerstone of enterprise RPA compliance. Storing plaintext passwords inside workflows, project arguments, or Data\Config.xlsx sheets violates regulatory frameworks including Sarbanes-Oxley (SOX), HIPAA, and PCI-DSS.

The Get Credential Activity Workflow

The Get Credential activity (contained within UiPath.System.Activities) retrieves an encrypted credential asset from Orchestrator:

' Conceptual invocation of Get Credential in UiPath Studio
GetCredential(
    FolderPath := "Finance/AccountsPayable",
    CredentialName := "SAP_ServiceAccount",
    out_Username := str_Username,              ' Type: System.String
    out_Password := sec_Password               ' Type: System.Security.SecureString
)

Deep Dive: System.Security.SecureString Mechanics

Why does UiPath output the password as a System.Security.SecureString rather than a standard System.String?

  • Limited Exposure: A standard .NET System.String is immutable and stays in managed memory until the garbage collector reclaims it, so a plaintext password can linger in memory dumps and crash logs. System.Security.SecureString keeps the characters out of ordinary strings and, on Windows, stores them encrypted.
  • Clearing on Dispose: When the SecureString object is disposed, its buffer is cleared.
  • UI Integration: Type Into accepts sec_Password in its Secure text field, so the workflow never needs to create a plaintext copy of the password.
String versus SecureString
String:       plaintext stays in managed memory until garbage collection
              and can show up in memory dumps or logs
SecureString: characters kept outside ordinary strings (encrypted on Windows);
              passed straight to Type Into's Secure Text field,
              so the workflow never holds a plaintext copy

Caution

Avoid Plaintext Conversion Anti-Patterns: Converting a SecureString to a plaintext String (e.g., using new System.Net.NetworkCredential(string.Empty, sec_Password).Password) completely circumvents its security architecture. Plaintext extraction should never be performed unless interacting with legacy REST libraries that strictly lack SecureString overloads.


4. Enterprise External Credential Stores

While the internal Orchestrator database provides robust AES-256 encryption for credentials, large enterprises frequently mandate that all machine identities, database passwords, and service account keys reside within a dedicated enterprise Privileged Access Management (PAM) vault.

UiPath Orchestrator supports direct integration with External Credential Stores, decoupling secret storage entirely from the Orchestrator SQL database.

+-----------------------------------------------------------------------------------+
|                      EXTERNAL CREDENTIAL STORE ARCHITECTURE                       |
|                                                                                   |
|  +---------------------+                                                          |
|  |   UiPath Robot      |                                                          |
|  |   (Execution Agent) |                                                          |
|  +----------┬----------+                                                          |
|             │ 1. Invokes Get Credential ("SAP_Vault_Asset")                       |
|             ▼                                                                     |
|  +---------------------+        2. Resolves Asset Definition                      |
|  | UiPath Orchestrator | ──────────────────────────────────────────┐              |
|  | (API & Gateway)     |                                           │              |
|  +----------▲----------+                                           ▼              |
|             │                                             +--------------------+  |
|             │ 4. Returns the secret to the                | Credential Store:  |  |
|             │    robot over its encrypted connection      | External Vault Ref |  |
|             │                                             +---------┬----------+  |
|             │                                                       │             |
|             │            3. Authenticates via mTLS / AppID          │             |
|             │               and queries Secret Identifier           │             |
|             │                                                       ▼             |
|  +----------┴------------------------------------------------------------------+  |
|  |                       ENTERPRISE CREDENTIAL VAULT                           |  |
|  |                                                                             |
|  |   [CyberArk Enterprise Password Vault]  /  [Azure Key Vault]                |
|  |   [HashiCorp Vault (KV Engine)]         /  [AWS Secrets Manager]            |
|  +-----------------------------------------------------------------------------+  |
+-----------------------------------------------------------------------------------+

Supported External Credential Store Platforms

  1. CyberArk Enterprise Password Vault:

    • Connects via CyberArk Central Credential Provider (CCP) or Application Identity Manager (AIM).
    • Configuration requires: Web Service URL, Application ID (AppID), Safe name, Folder, and Object name.
    • Orchestrator authenticates to CyberArk using client certificates (mTLS) or authorized IP address whitelisting.
  2. Azure Key Vault:

    • Connects via Microsoft Entra ID (Azure AD) service principals or Azure Managed Identities.
    • Configuration requires: Vault URI (https://<vault-name>.vault.azure.net/), Directory (Tenant) ID, Application (Client) ID, and Client Secret or X.509 Certificate.
  3. HashiCorp Vault:

    • Integrates using AppRole authentication or token-based authentication with Vault's Key-Value (KV) secrets engine (v1 and v2).
    • Configuration requires: Vault URL, Engine Path, Role ID, and Secret ID.
  4. AWS Secrets Manager:

    • Connects with AWS Identity and Access Management (IAM) access keys.
    • Configuration requires: AWS Region, Secret Name/ARN, Access Key ID, and Secret Access Key.
  5. Other stores: Orchestrator's credential store list also includes BeyondTrust, Delinea (Thycotic) Secret Server, and Google Secret Manager. Several integrations are read only: the vault administrator creates the secrets, and Orchestrator only reads them by their external names. External stores apply to Credential assets; Text, Bool, and Integer values stay in Orchestrator.

Runtime Resolution Flow

When an asset is backed by an External Credential Store, Orchestrator does not store the secret password in its database. Instead, Orchestrator stores only the metadata pointer (e.g., CyberArk Safe + Object name, or Azure Key Vault Secret Identifier):

  1. The Robot executes Get Credential and requests the asset from Orchestrator.
  2. Orchestrator looks up the asset record, recognizes that it is assigned to an external credential store, and identifies the target vault reference.
  3. Orchestrator establishes an outbound connection to the external vault using its enterprise service credentials.
  4. The external vault verifies Orchestrator's identity, evaluates vault access control policies, and returns the current secret payload.
  5. Orchestrator returns the secret to the requesting robot over its encrypted connection. For vaults inside the corporate network, the Orchestrator Credentials Proxy lets a cloud Orchestrator reach them without exposing the vault to the internet.

5. Credential Rotation & Audit Logging

Integrating an external vault raises one main operational question: how to handle automated password rotation without interrupting running automations.

Password Rotation

Because the secret lives in the vault, a PAM rotation takes effect on the next Get Credential call without changing the process or the asset:

  1. The vault rotates the service account password and updates the target application.
  2. The next Get Credential request makes Orchestrator read the current secret from the vault.
  3. The robot logs in with the new password; no package, asset, or configuration file changes.

A job that is already logged in keeps its session, so plan rotations outside critical processing windows or make the login workflow retry once with a freshly fetched credential.

Audit Trails

  • Orchestrator: the Audit page records who created, changed, or deleted assets, credential stores, and other entities, and job logs show which process ran under which account.
  • Vault: the external vault keeps its own record of every secret that Orchestrator's identity read.
  • Together, the two trails show who can change a credential, when the vault handed it out, and which job used it.

6. Architecture Comparison & Security Best Practices

Architectural AttributeInternal Orchestrator DatabaseExternal Credential Store (CyberArk / Azure Key)
Secret Storage LocationEncrypted within Orchestrator SQL ServerStored exclusively inside external enterprise vault
Encryption StandardAES 256 in OrchestratorWhatever the enterprise vault provides
Password RotationManual update via Orchestrator UI or APIAutomated rotation driven by corporate PAM policies
Operational OverheadLow; zero external infrastructure dependenciesModerate; requires vault provisioning and network peering
Network DependencyNone beyond OrchestratorThe vault must be reachable (directly or through the Credentials Proxy)
Typical ChoiceMost automationsOrganizations whose security policy requires every secret to live in a central PAM vault

Security Best Practices for Orchestrator Assets

  1. Enforce Least Privilege RBAC: Grant Assets View only to the accounts that need to read assets; credential assets use the same Assets permissions. Do not give robot roles Assets Create, Edit, or Delete.
  2. Never Pass Secrets as Plaintext Arguments: In modular workflows, pass credentials between .xaml files strictly as System.Security.SecureString variables. Never serialize credentials into JSON logs or queue item SpecificContent.
  3. Folder Isolation for Sensitive Assets: Keep sensitive HR, payroll, and payment assets in a folder branch where only the authorized people and robot accounts are assigned; inherited access cannot be removed in a subfolder.
  4. Watch for Failures: Alert on jobs that fault at login or on repeated Get Credential errors, which often signal an expired or rotated password.
Loading diagram...
Credential asset retrieval from an external credential store
Test Your Knowledge

A developer configures an asset named 'InvoiceTaxRate' in a Modern Folder with a Global Value of 0.08. An override value of 0.05 is specifically assigned to the user account 'CORP\Bot_Finance'. When an unattended job runs under 'CORP\Bot_Finance' and calls Get Asset for 'InvoiceTaxRate', what value is returned?

A

0.08, because global values always take precedence over user-specific overrides.

B

0.05, because Orchestrator resolves specific user account overrides before falling back to the global value.

C

0.13, because Orchestrator aggregates the global value and user override.

D

An exception is thrown because assets cannot have both a global value and a user override simultaneously.

Test Your Knowledge

Why does the Get Credential activity return the password as a System.Security.SecureString rather than a standard System.String?

A

SecureString automatically translates password characters into localized language encodings.

B

Standard strings cannot exceed 16 characters in UiPath Studio workflows.

C

SecureString bypasses the Windows operating system message queue to accelerate execution speed.

D

SecureString keeps the password out of ordinary strings (stored encrypted on Windows), which reduces exposure in memory dumps and logs.

Test Your Knowledge

When UiPath Orchestrator is integrated with an External Credential Store such as CyberArk or Azure Key Vault, where is the sensitive password secret physically stored?

A

Exclusively inside the external enterprise vault; Orchestrator stores only the vault reference metadata and fetches the secret at runtime.

B

In both the Orchestrator SQL database and the external vault via continuous two-way database replication.

C

Compiled directly into the robot's local NuGet project package during publishing from Studio.

D

In an unencrypted local XML cache on the host machine executing the robot process.

Sections you finish are checked off in the contents.