Credential 1
A short name so Theo knows what he is looking at, for example "Xero login" or "domain registrar".
If none of these look right, choose "Something else" and paste whatever you have. It is not a wrong answer and nothing is lost by using it. There is a box at the bottom if you want to ask about it.
Paste it exactly as it is. Spaces and line breaks are kept.
Many services give you the key as a pair. If yours came with a second value alongside the secret, an account SID, an access key ID, a client key, put that one here.
The secret half. Sometimes called an auth token, a secret key or an access token.
Sometimes called the application ID. Not secret, but nothing works without it.
Microsoft and Google apps usually have one. If you can see it, include it; it saves a round trip.
Whatever the thing is: a connection string, an SSH private key, a block of JSON, a list of recovery codes, an account number with its PIN, a licence key. Paste it exactly as it is; spaces and line breaks are kept. If it needs explaining, use the notes box below.
Does this expire?
Most logins do not. API keys and app passwords sometimes do. If you saw a date when you created it, put it here.
For example "the code is texted to whoever is on the front desk" or "this account is shared with the bookkeeper".