Skip to content
Patchbayagent routing bay

Credential vault

Bring your own keys. Everything you store is scoped to your session or account, encrypted before it reaches the database, and never sent back to the browser. Patchbay runs no provider calls with them, so nothing here is required to use the product.

Add a provider key

Keys are encrypted with AES-256-GCM before they reach the database and are never returned by any read endpoint. Patchbay does not call providers with them; they exist so your exported manifest and your own runtime stay self-contained.

Stored credentials

Loading credentials…

How the encryption works

  • Ciphertext is AES-256-GCM with a random 12-byte IV per key, and the auth tag is stored alongside it so tampering fails closed.
  • The encryption key is derived with SHA-256 from CREDENTIAL_ENCRYPTION_KEY, falling back to AUTH_SECRET. Rotating either invalidates stored keys, which is a deliberate destroy switch.
  • Read paths return a label, the last four characters, and a SHA-256 fingerprint of the ciphertext — enough to tell two keys apart, not enough to use either.
  • Keys never enter a URL, a log line, an error envelope, or an exported manifest.