Skip to main content
This guide covers the move of @outputai/credentials into @outputai/core. The package is no longer published: its API now lives at @outputai/core/credentials, and the worker resolves credential: env refs on its own, so the hook file that used to wire it up must go. Two smaller breaks come with it: the onBeforeWorkerStart hook is removed, and credentials errors are now non-retryable.

What changed

  • @outputai/credentials is replaced by the @outputai/core/credentials subpath. Nothing else needs installing: @outputai/core (and @outputai/output, which depends on it) ships it.
  • Importing the package no longer has a side effect. The worker resolves credential: env refs itself, after hook files, workflows, and activities are loaded and before the Temporal worker starts.
  • The encrypted YAML provider is the default. setProvider() is only needed to plug in a custom provider.
  • The exports were trimmed to what projects use. See Removed exports.
  • MissingKeyError, MissingCredentialError, InvalidCredentialsKeyError, and MalformedCredentialsKeyError now extend FatalError.
  • A missing or invalid key while resolving credential: env refs now stops the worker at startup. Before, the error was logged and the worker started with the refs unresolved.
  • onBeforeWorkerStart is removed from @outputai/core/hooks.

Migration steps

Remove the credentials hook file entry

Projects scaffolded before v0.15.0 list a hook file from the credentials package in package.json:
The file no longer exists, so the worker fails to start while the entry is there. Remove it by hand, or run:
output fix drops every outputai.hookFiles entry pointing into @outputai/credentials.

Delete hook files that only import the package

Some projects register credentials with a hook file of their own instead:
If that is all the file does, delete it and remove its entry from outputai.hookFiles. If it does more, remove only the import.

Update imports

Replace every import of @outputai/credentials with @outputai/core/credentials, including module mocks in tests:

Remove the dependency

Delete @outputai/credentials from dependencies, devDependencies, and peerDependencies in package.json, then reinstall. If your project depends on @outputai/core directly rather than through @outputai/output, bump it to 0.15.0.

Removed exports

Replace onBeforeWorkerStart

The hook existed to resolve credential: env refs, which the worker now does directly. Move any other handler body to the top level of its hook file, where it runs when the worker loads the file:
Hook files load before credential: env refs are resolved. A handler that read a resolved env var such as process.env.ANTHROPIC_API_KEY sees the raw credential:... value at the top level. Read the secret with credentials.get() instead, or defer the read until first use.

Re-check retries around credentials errors

A step that fails on a missing key, a key that cannot decrypt the file, a malformed key, or a missing required credential now fails on its first attempt instead of running through its retry policy. These failures are deterministic, so retries could not succeed. If you relied on a retry to pick up a key deployed mid-run, restart the workflow after deploying the key instead.

Make sure the worker has its key

If your .env uses credential: refs, the worker now exits at startup when the matching key is missing or wrong. Set OUTPUT_CREDENTIALS_KEY (or OUTPUT_CREDENTIALS_KEY_<ENVIRONMENT>) or provide the key file before deploying. See Credentials.