@outputai/credentials into @outputai/core. The package is no longer published: its API now lives at @outputai/core/credentials, and the worker resolves credential: env refs on its own, so the hook file that used to wire it up must go.
Two smaller breaks come with it: the onBeforeWorkerStart hook is removed, and credentials errors are now non-retryable.
What changed
@outputai/credentialsis replaced by the@outputai/core/credentialssubpath. Nothing else needs installing:@outputai/core(and@outputai/output, which depends on it) ships it.- Importing the package no longer has a side effect. The worker resolves
credential:env refs itself, after hook files, workflows, and activities are loaded and before the Temporal worker starts. - The encrypted YAML provider is the default.
setProvider()is only needed to plug in a custom provider. - The exports were trimmed to what projects use. See Removed exports.
MissingKeyError,MissingCredentialError,InvalidCredentialsKeyError, andMalformedCredentialsKeyErrornow extendFatalError.- A missing or invalid key while resolving
credential:env refs now stops the worker at startup. Before, the error was logged and the worker started with the refs unresolved. onBeforeWorkerStartis removed from@outputai/core/hooks.
Migration steps
Remove the credentials hook file entry
Projects scaffolded before v0.15.0 list a hook file from the credentials package inpackage.json:
output fix drops every outputai.hookFiles entry pointing into @outputai/credentials.
Delete hook files that only import the package
Some projects register credentials with a hook file of their own instead:outputai.hookFiles. If it does more, remove only the import.
Update imports
Replace every import of@outputai/credentials with @outputai/core/credentials, including module mocks in tests:
Remove the dependency
Delete@outputai/credentials from dependencies, devDependencies, and peerDependencies in package.json, then reinstall. If your project depends on @outputai/core directly rather than through @outputai/output, bump it to 0.15.0.
Removed exports
Replace onBeforeWorkerStart
The hook existed to resolve credential: env refs, which the worker now does directly. Move any other handler body to the top level of its hook file, where it runs when the worker loads the file:
credential: env refs are resolved. A handler that read a resolved env var such as process.env.ANTHROPIC_API_KEY sees the raw credential:... value at the top level. Read the secret with credentials.get() instead, or defer the read until first use.
Re-check retries around credentials errors
A step that fails on a missing key, a key that cannot decrypt the file, a malformed key, or a missing required credential now fails on its first attempt instead of running through its retry policy. These failures are deterministic, so retries could not succeed. If you relied on a retry to pick up a key deployed mid-run, restart the workflow after deploying the key instead.Make sure the worker has its key
If your.env uses credential: refs, the worker now exits at startup when the matching key is missing or wrong. Set OUTPUT_CREDENTIALS_KEY (or OUTPUT_CREDENTIALS_KEY_<ENVIRONMENT>) or provide the key file before deploying. See Credentials.