Skip to content
1 minute readSecurityAgent-ready

Function credentials are now encrypted at rest

Authentication configuration stored with each function is now encrypted at rest, so credentials are protected even at the storage layer.

Credentials attached to functions are encrypted before they are stored, adding a layer of protection beyond access controls.

  • New and updated function authentication configurations are encrypted when saved, and existing ones are encrypted by a one-time migration that runs with this release
  • No API contract changes; existing integrations continue to work without modification
  • Combined with the existing write-only policy, credentials are neither readable nor recoverable after they are saved