Mojo UpDocs
Security and trust

Encryption and keys

How the Mojo Up platform protects data in transit and at rest, and how tokens, secrets and remote-control requests are secured.

In transit

Every connection to the platform uses HTTPS: the console, the API, and the relay connection each workbench and node keeps open. Workbenches and nodes only ever connect out to the platform; nothing connects in to them.

Self-hosted AIOE can also carry traffic over its own WireGuard overlay network, which encrypts it end to end between members. See The overlay and relays.

Tokens

TokenWhat it isHow it is kept
Device tokensA workbench's or node's own access, issued when someone approves itRandom, with a recognisable prefix (aioe_at_ for access, aioe_rt_ for refresh), and stored only as a SHA-256 hash
Device codesThe short code a person approvesShort-lived: ten minutes for a workbench, 24 hours for a node (the defaults)
Mojo Up AI Cloud sessionsYour browser's or phone's accessStored only as hashes. Access tokens last 15 minutes; refresh tokens 30 days, replaced on every use, and the whole session ends if an old one is reused
Identity provider tokensOn self-hosted AIOE, people sign in with tokens from your identity providerVerified against your provider's published keys on every request; the token's issuer selects the organisation

The prefixes make a leaked token easy to recognise, for example by secret scanning in your repositories.

Tokens bound to the machine

A workbench or node can bind its access to a private key that never leaves the machine, using DPoP (RFC 9449, with ES256 or EdDSA proofs). Every request then carries a fresh proof signed by that key. A copied token is useless on any other machine. The console shows when a workbench's access is bound this way.

Secrets

Secrets the platform holds for your agents' tools, such as API keys, are encrypted with AES-256-GCM under a key the platform holds apart from the database. They are released only to signed-in workbenches and nodes of the same organisation, by name. On self-hosted AIOE that key is yours (AIOE_SECRETS_KEY); keep it in your own secret store. On Mojo Up AI Cloud, Mojo Up's keys and service secrets are kept in Azure Key Vault.

Remote-control requests

Every request the platform forwards to a workbench is signed with the platform's Ed25519 key, for that workbench and exactly the scopes it was approved with. The workbench checks the signature against the keys the platform publishes, and refuses anything unsigned or outside its scopes. See How remote control works.

At rest

The platform's records live in PostgreSQL. Mojo Up AI Cloud uses Azure Database for PostgreSQL in Australia East, which encrypts its storage at rest. On self-hosted AIOE, encryption at rest is a property of the database service and disks you choose.

The audit trail

Each row of the audit trail carries a SHA-256 hash of the row before it, so changing, removing or reordering any row is detectable. See The audit trail.

On this page