Encryption and keys
How the Mojo Up platform protects data in transit and at rest, and how tokens, secrets and remote-control requests are secured.
In transit
Every connection to the platform uses HTTPS: the console, the API, and the relay connection each workbench and node keeps open. Workbenches and nodes only ever connect out to the platform; nothing connects in to them.
Self-hosted AIOE can also carry traffic over its own WireGuard overlay network, which encrypts it end to end between members. See The overlay and relays.
Tokens
| Token | What it is | How it is kept |
|---|---|---|
| Device tokens | A workbench's or node's own access, issued when someone approves it | Random, with a recognisable prefix (aioe_at_ for access, aioe_rt_ for refresh), and stored only as a SHA-256 hash |
| Device codes | The short code a person approves | Short-lived: ten minutes for a workbench, 24 hours for a node (the defaults) |
| Mojo Up AI Cloud sessions | Your browser's or phone's access | Stored only as hashes. Access tokens last 15 minutes; refresh tokens 30 days, replaced on every use, and the whole session ends if an old one is reused |
| Identity provider tokens | On self-hosted AIOE, people sign in with tokens from your identity provider | Verified against your provider's published keys on every request; the token's issuer selects the organisation |
The prefixes make a leaked token easy to recognise, for example by secret scanning in your repositories.
Tokens bound to the machine
A workbench or node can bind its access to a private key that never leaves the machine, using DPoP (RFC 9449, with ES256 or EdDSA proofs). Every request then carries a fresh proof signed by that key. A copied token is useless on any other machine. The console shows when a workbench's access is bound this way.
Secrets
Secrets the platform holds for your agents' tools, such as API keys, are encrypted with AES-256-GCM under a key the platform holds apart from the database. They are released only to signed-in workbenches and nodes of the same organisation, by name. On self-hosted AIOE that key is yours (AIOE_SECRETS_KEY); keep it in your own secret store. On Mojo Up AI Cloud, Mojo Up's keys and service secrets are kept in Azure Key Vault.
Remote-control requests
Every request the platform forwards to a workbench is signed with the platform's Ed25519 key, for that workbench and exactly the scopes it was approved with. The workbench checks the signature against the keys the platform publishes, and refuses anything unsigned or outside its scopes. See How remote control works.
At rest
The platform's records live in PostgreSQL. Mojo Up AI Cloud uses Azure Database for PostgreSQL in Australia East, which encrypts its storage at rest. On self-hosted AIOE, encryption at rest is a property of the database service and disks you choose.
The audit trail
Each row of the audit trail carries a SHA-256 hash of the row before it, so changing, removing or reordering any row is detectable. See The audit trail.