Encryption
- +API keys — only a SHA-256 hash is stored. The plaintext key is returned once when the key is created or rotated.
- +Scheduled-export credentials — destination secrets are encrypted at the application layer with the configured encryption key.
- +Authentication — Clerk session tokens are verified by the API; API keys can be restricted by scope, expiry, rate, and source IP.