corsair.ts
Auth types
Choose the auth type for each integration:API key
For integrations that use static API keys or bot tokens.OAuth 2.0
For integrations that require user authorization.Managed
Corsair hosts the OAuth app, so you register nothing in the provider console. Enable it per plugin withauthType: "managed". Available for managed plugins on Hub.
Automatic token refresh
When using OAuth, tokens expire. Corsair handles this automatically:- Before making a request, checks if the token is expired
- If expired, uses the refresh token to get a new access token
- Stores the new token and continues with the request
Envelope encryption
Corsair uses envelope encryption to protect credentials:- You set one KEK (Key Encryption Key) in your environment variables
- Each connection gets its own DEK (Data Encryption Key)
- All credentials are encrypted with the connection’s DEK
- The DEK is encrypted with your KEK
.env
This holds whether you self-host or use Hub. Hub is a relay for connect, approval, and webhook surfaces; it stores none of your credentials. Encrypted tokens are persisted only in your database in both modes.
Bring Your Own KMS
If you’re using a Key Management Service (AWS KMS, Google Cloud KMS, etc.), you can opt out of Corsair’s built-in encryption.corsair.ts
Multi-tenant credentials
With multi-tenancy, each tenant has their own credentials stored securely.example.ts