OTA Channel Manager guide

Encrypted Storage for Your Channel Credentials

A channel credentials vault keeps your OTA connection keys encrypted, out of the app's reach, with a history kept across every key change.

Your channel keys belong to your hotel, so they live in an encrypted vault, not a config file.

How it works

What you see on screen

The client ID, which environment, the key's fingerprint and who saved it. That is enough to tell which key is active, without ever showing the key itself.

Changing a key

Anyone whose role allows it can change a key. The old key is retired, the replacement is used from the very next call, and the history of which key was active when is kept. Both the push service and the API use this single vault, so you only ever update a key once.

Kept apart

The vault has its own schema and its own permissions. Code that reads the vault is never bundled with anything your users can run, and an automated test checks that the application cannot read from it.

Other OTA Channel Manager guides