Per-agent secrets
Secrets are encrypted before they’re written to the database and decrypted only when injected into a container’s environment at deploy time. Plaintext exists in memory for that deploy call and then inside the running container — nowhere else.- Stored ciphertext-only. A database dump never exposes raw values.
- Decryption happens once, server-side, immediately before the container starts.
- Rotating a secret and restarting the agent re-injects the new value. Nothing is cached outside the container’s environment.
Platform identity secrets
Nasiko supports SSO through any OIDC-compliant identity provider (Entra ID, Okta, Auth0, Keycloak, and others). The client secret is encrypted at rest under the same scheme, whether configured via environment variables at deploy time or the admin settings API at runtime. See SSO setup, including how group claims can place users into roles, teams, and departments automatically.Where this fits
- Access control overview — who can read and rotate secrets
- Agent hosting — how secrets flow into a running container
