Core concepts
Bring your own key
Your provider account, sealed with KMS.
A provider credential is sealed on write under a per-tenant encryption context. The wrapping key never leaves the KMS, and the plaintext exists only inside a callback that lasts one request.
ts
The resolved cache is in-process and never Redis: Redis persists to disk, replicates over a network, and appears in MONITOR.
Rotation
A credential is replaced, never read back. Add the new one, let it verify, then revoke the old, the gateway resolves the active one per request.