Where Sume stores connector tokens: AES-256-GCM, never in status
Sume encrypts connector tokens and pending PKCE data with AES-256-GCM, fails closed without a key, and its status endpoint returns no credentials.

Sume stores connector tokens and pending PKCE material in the product database using an AES-256-GCM envelope. If the encryption configuration is missing, a live connect fails closed. The status endpoint returns no credentials: for a disconnected provider it returns an empty object, and for a connected one only public status plus the registered tool names.
What is stored
Migration 0099_workspace_integrations.sql adds a table keyed by (workspace_id, provider). Personal workspace ids are user ids and team ids are Clerk organization ids. The web app and the agent runtime read the same database through shared pools, and both need the same encryption key so that the agent can decrypt what web saved.
What the API returns
GET /api/integrations returns the connector list, public status ({} when disconnected), management capability and the registered read-tool names. Responses are uncached, and a mutation needs a matching Origin and admin capability.
| Endpoint | Behavior |
|---|---|
GET /api/integrations | List, public status, tool names |
POST /api/integrations/{provider}/connect | Install URL and state cookie |
GET /api/integrations/{provider}/callback | Code exchange and redirect |
POST /api/integrations/{provider}/disconnect | Removes connection and pending authorization |
Fixtures store no token
Development sample connections store no token at all and identify themselves as sample data. They are development-only, and in production identity they are not listed or executed.
What this means for your risk review
A security reviewer can read three facts straight from the docs: tokens are encrypted at rest, status never echoes them, and the allowlist limits what an agent can do with a token. They cannot read from the docs how the provider side revokes a grant, so cover that in your own offboarding checklist, as in what to do about an exposed key.
Operator notes
Web and the agent runtime must share the same token envelope and product storage. In development, the encryption key is the same value on both sides; after environment variables change, the web deployment has to be rebuilt before a test is meaningful. Those are operator tasks, not something a workspace admin does.
As a user, your part is small: connect with the right admin account, disconnect when finished, and treat API keys as separate secrets.
Related posts
More in Integrations
- Sume Slack connector: read and search only, no chat:write
The Sume Slack integration gives agents search and read tools over a user token. It requests no chat:write, reactions, canvas, list or file-upload scopes.
- Tally webhook to a Sume music job: verify, dedupe, return 200 fast
Tally signs with base64 HMAC-SHA256, waits 10 s and retries up to a day. Verify the signature, use eventId as the Idempotency-Key, then start the Sume job.
- Telegram sendAudio for a Sume track: URL 20 MB, upload 50 MB
Telegram can fetch a sendAudio file from a URL up to 20 MB, or accept an upload up to 50 MB. Pass the Sume artifact link first; upload only as a fallback.
- Threads link limit: 5 unique URLs per post, checked before publish
Threads allows 5 unique URLs per post and returns THREADS_API__LINK_LIMIT_EXCEEDED past that. Count unique links in the caption before posting a Sume clip.
Written by Sume