Encrypted Storage for Your Channel Credentials
A channel credentials vault keeps your OTA connection keys encrypted, out of the app's reach, with a history kept across every key change.
Your channel keys belong to your hotel, so they live in an encrypted vault, not a config file.
How it works
- The vault is its own section of the database and is encrypted on disk.
- Only the functions that sign a channel call can read the key.
- The key is never sent to a browser.
What you see on screen
The client ID, which environment, the key's fingerprint and who saved it. That is enough to tell which key is active, without ever showing the key itself.
Changing a key
Anyone whose role allows it can change a key. The old key is retired, the replacement is used from the very next call, and the history of which key was active when is kept. Both the push service and the API use this single vault, so you only ever update a key once.
Kept apart
The vault has its own schema and its own permissions. Code that reads the vault is never bundled with anything your users can run, and an automated test checks that the application cannot read from it.
