Secret fields, such as API keys, App Passwords, bot tokens, service-account JSON files, .p8 keys, app secrets and Meta System User tokens, are encrypted when stored and shown hidden on the card. The change history keeps only redacted values.
Facebook and Instagram: the System User token stays on Wiro's servers. Wiro uses it to get Page-level tokens, and the agent receives only those.
Give the least access needed: for example a dedicated Gmail account with an App Password, or a service account shared only on the calendars or folders the agent needs.
You stay in control: you can revoke a key or token at the provider at any time, and Disconnect removes Wiro's copy (see connecting integrations).
Details: credential security.
