Secret URLs are returned once
Direct Heartbeat and Webhook creation returns the new secret URL only in the first successful response. Store it immediately in the application or deployment secret store using the exact environment variable name returned by the tool.
Keep it out of chat replies, source files, repository manifests, analytics and logs. A support request should describe the problem without including the secret URL.
Creation timed out
A timeout does not prove that creation failed. The server may have completed the operation before the response was lost.
Retry with the same idempotency key and identical input. A retry returns the resource mapping without revealing the secret again. Using a new key can create a duplicate resource, so do not generate a fresh key merely because the first response did not arrive.
The resource exists, but the credential is missing
Recover the lost credential through the MonoDuty dashboard. MCP cannot retrieve or rotate existing credentials. Do not ask the assistant to recover it from logs or paste unrelated credentials into the connection.
Review the resource mapping and dashboard state before deciding whether anything needs to be recreated. If you cannot resolve the mismatch, contact support with the operation, approximate time and sanitized error details.
Avoid the next failure
Before creation, decide where the returned environment variable will be stored. After creation, confirm that the application references that secret-store entry and then run the documented integration test. Do not print the secret value as a way to prove it was saved.
References
MonoDuty MCP setup and permissions · MonoDuty MCP overview
Reviewed against MonoDuty documentation on September 30, 2026.