HL_LLM_PROXY_SECRETS_AZURE_SECRET_<SETTING_NAME>. The suffix is the Runtime setting name — the same rule as AWS.
Hybrid token refresh reads HL_LLM_PROXY_CLIENT_ID and HL_LLM_PROXY_CLIENT_SECRET. See Deployment.
Names such as HL_LLM_PROXY_SECRETS_AZURE_SECRET_HL_CLIENT_ID and HL_LLM_PROXY_SECRETS_AZURE_SECRET_HL_CLIENT_SECRET still fetch values from Key Vault, but they do not populate hybrid authentication.
Example Azure Key Vault configurations
Environment Variables
Disabled
License only. Use this when Runtime is not sending metadata to HiddenLayer.Hybrid
License plus the twoHL_LLM_PROXY_CLIENT_* names. Hybrid token refresh requires these setting names.

