Credentials and encryption

Pura-owned account key

The one internal subscription key is encrypted at rest on Pura and never returned through OAuth, inference, the SDK or webhooks. Partners have no key-decryption step. User-visible pay-as-you-go keys are a separate product.

Partner storage

Store confidential client secrets in your server secret manager. Use an encrypted per-user OAuth TokenStore and persist refresh rotation atomically. Never log authorization codes, bearer tokens or secrets. Browser apps cannot keep a confidential secret; use a public client or a backend session.

Internal key rotation

Pura operators configure SUBSCRIPTION_KEY_ENCRYPTION_KEYS as a JSON array of Fernet keys. The first encrypts new credentials; all listed keys decrypt existing credentials during rotation. Keep prior keys until existing ciphertext has been migrated. Missing or invalid configuration prevents paid checkout and provisioning.