Authentication & BYOK Security
AVAILABLENaagmani separates authentication into two distinct operational planes:
- Management / Control Plane: OAuth2 SSO (Google, GitHub, SAML/OIDC) and Personal Access Tokens for portal users.
- Inference / Data Plane: Project Service Tokens (
nst_live_...) for microservices, background jobs, and agents.
Bring-Your-Own-Key (BYOK) Security Vault #
When you register provider API keys in Naagmani:
- Keys are encrypted in memory prior to database persistence.
- Database records store only ciphertext and cryptographic hashes for indexing.
- Key material is decrypted exclusively inside the Data Plane memory enclave during an active provider dispatch and wiped immediately after socket transmission.