Propolis
Security & trust

What we hold, how we hold it, and what we won't do.

Propolis exists to hold secrets on your behalf, so you deserve a plain description of how. This page is written to be read, not skimmed past. If anything here is unclear, that is a bug.

What Propolis stores

  • Upstream OAuth grants. The refresh token and current access token for each service you connect, plus the raw token response. All three are encrypted at rest with the application key and are hidden from every API response and serialisation path.
  • Propolis API tokens. Stored as SHA-256 hashes, the same way Laravel Sanctum always does. The plaintext is shown to you once at creation and never again.
  • Access logs. One append-only file per connector: timestamp, token name, tool, the arguments the agent sent (trimmed at 4 KB), the outcome, and the HTTP status from the service. Responses from the service are not stored.
  • Your account. Name, email, a hashed password, and optional two-factor secrets and recovery codes, encrypted.

What your agents can see

Exactly one thing: the Propolis token you gave them. On every call, Propolis resolves that token to your account, finds the connector, and attaches the upstream access token server-side. The refresh token is never transmitted anywhere except to the service that issued it, during renewal.

One exception, and it is opt-in
The Claude Code connector page offers to show you the stored OAuth token so you can paste it directly onto a machine. That is your choice, clearly labelled, and the forwarder option next to it keeps the token on the server instead.

Controls you hold

Per-tool switches

Turn any tool off for a connector. Calls to it are refused at the broker and logged as blocked.

Token scoping

Each Propolis token names the connectors it may use. A token that is not scoped to a connector cannot reach it.

Disconnect

Clears the stored credential immediately. The connector row stays so you can reconnect without losing its history.

Delete

Removes the connector, its credential and its tool settings. Delete a Propolis token and every agent using it is locked out on the next request.

The audit trail

Every brokered tool call is written to your access log in the background, including the ones Propolis refused. The dashboard reads the same files you can download, so what you see on screen is what is on disk. Figures on the dashboard are cached for up to a minute and say so; the refresh button re-reads the logs on demand.

Logs are stored per account on the application's file storage. In production that is a shared object store, and the dashboard warns you if it is ever misconfigured to a container-local disk where entries could be lost.

Isolation

Every connector, credential, tool setting and log belongs to exactly one account. Every read and write path checks that ownership, and the test suite asserts a stranger gets a 403 or 404 on each one. There is no sharing, no teams, and no admin view of other people's grants.

What we don't do

  • We do not store the responses your agents get back from services.
  • We do not use your grants for anything except the calls your tokens make.
  • We do not retry a call with a credential we know is broken. It is marked, surfaced on your dashboard, and waits for you.
  • We do not offer team sharing yet. One person, one account, one set of grants. We would rather ship that carefully than early.
Found something?

Propolis is early and open about it. If you spot a gap in anything above, tell us before you tell anyone else and we will fix it quickly and credit you if you like.