Overview
Power Automate flows that send recording triggers to the Luware Recording API need a secure place to keep the API credentials. An Azure Key Vault does this job. The flow reads the API key and password from the vault at runtime, so they never appear in plain text inside the flow itself.
You create the vault, give your App Registration read access to it, and then store the two Luware Recording credentials as secrets.
Prerequisites
Have the following ready before you start:
- Luware Recording API Key: provided by your Luware Engineer.
- Luware Recording API User Password: provided by your Luware Engineer.
- Azure Entra ID App Registration: this must exist before you configure the vault, because you grant it access in the steps below. Contact Luware if you need the separate guide for creating it.
- An Azure account with permission to create Key Vaults and manage their access, for example Contributor or Owner on the target resource group.
Creating the Azure Key Vault
☝ Use the Vault Access Policy Permission Model
New Key Vaults default to the Azure role-based access control permission model, which hides the Access policies page used later in this guide. When you create the vault, open the Access configuration tab and set the permission model to Vault access policy. If you reuse an existing vault, check this setting under Settings > Access configuration.
Sign in to the Azure Portal with an account that has the permissions listed in the prerequisites.
Open the Key Vaults service.
Select Create. Fill in the subscription, resource group, vault name, region and pricing tier to suit your organization's standards, then select Review + create followed by Create. You can also use an existing Key Vault, as long as it uses the vault access policy model.

Granting the App Registration Access
The Power Automate flow authenticates to the vault as your App Registration, so that identity needs read access to the secrets.
Once the vault is deployed, open it and go to Access policies. Select Create (shown as Add Access Policy in some portal versions).

Set Secret permissions and Key permissions to Get and List only. This lets the App Registration read the Luware Recording credentials without being able to change or delete them.


Open the principal selector (Select principal).

Search for the Azure Entra ID App Registration you created for the Luware Recording selective recording Power Automate flow, and select it.

Select Add (or Create) to apply the policy.

Back on the Access policies page, select Save if prompted. The new policy appears in the list with the App Registration as the principal.

Creating the Secrets
The flow expects two secrets, one for the API key and one for the API user password.
💡 Secret Names Must Match Exactly
The Power Automate flow looks up each secret by name. A typo or a change in capitalization causes the lookup to fail and no recording triggers reach Luware Recording. Copy the names below exactly as shown.
In the Key Vault, go to Secrets and select Generate/Import.
Name the first secret LuwareRecordingAPIKey and paste the API key from your Luware Engineer into Secret value. Select Create.

Select Generate/Import again. Name the second secret LuwareRecordingAPIPassword and paste the API user password from your Luware Engineer into Secret value. Select Create.

Next Steps
Note down the Key Vault name. You need it when you configure the Key Vault connection in the Power Automate flow.