# Credentials, Shared Libraries, and Declarative Pipelines

**URL:** <https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705>\
**Category:** Ask a question\
**Created:** [June 10, 2022, 8:43pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705 "2022-06-10T20:43:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![zlacelle](https://avatars.discourse-cdn.com/v4/letter/z/f4b2a3/32.png) [@zlacelle](https://community.jenkins.io/u/zlacelle)\
**Post date:** [June 10, 2022, 8:43pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705/1 "2022-06-10T20:43:03Z")

</div>

I have a declarative pipeline that uses some shared library I created to perform some commands requiring authentication. To perform these tasks, I can do it directly from my Jenkinsfile using the normal credentials syntax:

```auto
environment
{
  CREDS = credentials('my_special_creds')
}
...
step
{
  sh('mycommand.sh --username $CREDS_USR --password $CREDS_PSW')
}

```

However, I can’t seem to get them passed into my shared library safely (i.e. avoiding Groovy double-quote expansion). The problem seems to be passing them in as arguments.

It doesn’t work to do this:  
mylib.groovy

```auto
call(Map params = [:])
{
  sh('mycommand.sh --username $params.user --password $params.pass')
}

```

(this seems to result in Groovy replacing $params with ‘’, so the command is “mycommand.sh --username .user --password .pass”

I also tried passing as separate strings, thinking it was a period-breaking-the-dereference issue. Didn’t work.

How should I pass credentials into Jenkins Shared Library calls within a Declarative Pipeline?

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [June 10, 2022, 9:10pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705/2 "2022-06-10T21:10:34Z")

</div>

> [@zlacelle](#):
>
> ```auto
> sh('mycommand.sh --username $params.user --password $params.pass')
> 
> ```

single quotes are not evaluated, so bash is trying to evaluate an environmental variable called $params. why not pass in the credential id, and use withCredentials {} block to create env variables with that credential just for that scope?

---

<div class="post-metadata">

**Author:** ![zlacelle](https://avatars.discourse-cdn.com/v4/letter/z/f4b2a3/32.png) [@zlacelle](https://community.jenkins.io/u/zlacelle)\
**Post date:** [June 10, 2022, 9:22pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705/3 "2022-06-10T21:22:34Z")

</div>

I think that’s a scripted pipeline thing, right? I’m using Declarative syntax. Thus the environment { credentials() } approach, vs withCredentials.

---

<div class="post-metadata">

**Author:** ![halkeye](https://dub1.discourse-cdn.com/flex013/user_avatar/community.jenkins.io/halkeye/32/8_2.png) [@halkeye](https://community.jenkins.io/u/halkeye)\
**Post date:** [June 10, 2022, 9:27pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705/4 "2022-06-10T21:27:06Z")

</div>

shared libraries are always scripted

edit: actually not always, but afaik you can only have one `pipeline {}` and once you go into the function your scripted.

---

<div class="post-metadata">

**Author:** ![zlacelle](https://avatars.discourse-cdn.com/v4/letter/z/f4b2a3/32.png) [@zlacelle](https://community.jenkins.io/u/zlacelle)\
**Post date:** [June 13, 2022, 2:18pm UTC](https://community.jenkins.io/t/credentials-shared-libraries-and-declarative-pipelines/2705/5 "2022-06-13T14:18:00Z")

</div>

You’re right! It does seem that once we enter the shared library, withCredentials() works, even though the rest of the pipeline is declarative. This was confusing for me because, in the Declarative pipeline file, you cannot use the scripted Groovy shared library calls (e.g. I can’t do a “myclass.function()”, I just have to call “myclass()” and implement the call() function). So, while I am limited in how I can call shared libraries, once inside that call() function, apparently all scripting goes 🙂

Thanks for the support, and hopefully this helps someone else coming across this issue.
