SECRETS
Credentials are encrypted before database storage
OAuth refresh tokens, SMTP and IMAP passwords, and OpenRouter API keys are protected with authenticated encryption using the deployment's token encryption key. The interface never returns stored secret values in plaintext.
- Unique nonce per encrypted value
- Authentication tag detects tampering
- Masked settings display
- Disconnect removes channel access