Connector security

How keys and sign-in are stored and limited, what is logged, and what is done to results before the assistant sees them.

ConceptDeveloperChecked 2026-10-10

Credentials are stored as one-way hashes, scoped with no wildcard, counted per account, and every call is recorded as a shape without its values.

Credentials

  • Hashed. Keys and OAuth tokens are stored as SHA-256 hashes. The plaintext is shown once and cannot be recovered from the database.
  • Shape check first. A value that does not look like a key is rejected before any lookup.
  • Expiry in code. Expired tokens are refused at the check. Rows are kept so a token can still be investigated.
  • Account status. Suspended or closed accounts lose every credential at once. The approved sign-in list is re-checked on every call.
  • Revocation takes effect on the next call.

Permissions

There is no all-access permission, and an empty list can do nothing. A typo in a permission name drops it rather than widening the key. New tools never add themselves to an existing key. See Permissions and limits.

OAuth

Public clients only, PKCE S256, exact redirect matching with loopback allowed on any port, a 5 minute single-use code, a 1 hour access token and a refresh token that rotates on every use. Reusing an old refresh token is refused.

What is logged

Every call writes one row: the tool, the account, the number of rows, how long it took, a reference, and the shape of the arguments. Shape means the names of the arguments, whether each is text or a number, and the length of text. It never holds a search term, a name or a value. Rows are kept 90 days. Refused credentials are logged with the first 12 characters at most, the address and the time, for 30 days. GET /market/tokens/usage returns your own account's recent calls with their shapes, today's counts, your limits and any alerts, and nobody else's. The key window in the app shows only the counts for today.

Alerts and the kill switch

A watcher raises alerts for unusual patterns, such as heavy extraction. Alerts for your account come back from that same route. The connector can be switched off without a deploy, and while it is off every call gets 503 unavailable.

Results are cleaned

Everything returned passes through two steps. The first defangs text that someone outside Adapt could have written, so it cannot pass as an instruction. The second removes anything that says where a fact came from. Errors give a reference and the class of failure, never the cause.

Limits

Calls and rows are counted per account, so one account's loop cannot slow another. See Rate limits, credits and allowances. Search is masked, and a record's contact details need a reveal.

What we cannot promise

We see the calls your assistant makes, such as the search terms it sends, because we have to run them. We do not see the rest of your conversation. What your assistant does with what it reads is up to that assistant and its provider.