Core concepts

Bring your own key

Your provider account, sealed with KMS.

A provider credential is sealed on write under a per-tenant encryption context. The wrapping key never leaves the KMS, and the plaintext exists only inside a callback that lasts one request.

ts

The resolved cache is in-process and never Redis: Redis persists to disk, replicates over a network, and appears in MONITOR.

Rotation

A credential is replaced, never read back. Add the new one, let it verify, then revoke the old, the gateway resolves the active one per request.