The OpenBao Secrets service is fully integrated with the EWC IAM. Users can authenticate using their tenancy credentials through the OIDC provider. Follow the steps below to access the system.
Navigate to:
https://secrets-val.europeanweather.cloud/ui/vault/auth?with=oidc
This page displays the available authentication methods.
Choose OIDC from the list of authentication options. This method enables login through the EWC IAM.
![]()
Click “Sign in with OIDC provider”. You will be redirected to a new window managed by the EWC IAM.
In the IAM login window:
Provide your tenancy name
Proceed with your EWC IAM credentials or Federated IAM (e.g. ECMWF SSO, EUMETSAT EOPortal)
Once authenticated, you will be returned to the OpenBao UI with a valid session token.
After successful login, you will arrive to the root namespace of your tenancy.

you don't have to do anything here, you have to switch to your namespace on the low left corner → select your tenancy name. ![]()
At the point you will arrive to your tenancy namespace, where you have secret engines enabled: EWC Secret Manager - Mount/Secret Engine

You will have access to all resources assigned to your tenancy. (depending on the roles you have you might have access to more or less resources, please check EWC Secret Manager - User Roles and Permissions )