Security

Auth, isolation, secrets, audit logging, and safe production config.

Synapass is infrastructure that holds provider credentials and customer prompts. It is built to fail closed: unsafe production configuration refuses to start, secrets are referenced rather than stored, and every control-plane mutation leaves an audit trail.

Authentication#

  • API keys are SHA-256 digests. The plaintext is returned exactly once at creation and can never be retrieved afterwards. Save it now or mint again.
  • Scopes narrow by method and path. A key with the inference scope calls /v1/*; admin surfaces require admin scopes. A valid credential without the required scope gets 403 permission_error, not a silent pass.
  • The header name is configurable (auth.header_name) for deployments behind a proxy that reserves Authorization.
  • Minimum key length is enforced before lookup (auth.min_key_length), rejecting hand-typed placeholders without a database round trip.
  • Validated keys are cached (auth.cache_ttl, default 30s). Revocation drops the cache entry, so a revoked key stops working immediately.
  • Console login has no defaults. The first visit creates a single administrator whose password is stored as an Argon2id hash; the setup screen then closes permanently, and failed attempts lock the account temporarily. Lost credentials are a database operation — there is no reset link, by design.

Tenant isolation#

Isolation is structural, not conventional:

  • routing decisions are computed per tenant,
  • cache keys embed the tenant, so a hit never crosses tenants,
  • Redis namespaces separate limits, budgets, and health state.

Policy enforcement#

Denials return 403/429 with an explaining message and zero provider calls. The rule that fired is named — in the response, the error envelope, and the request log.

Secret handling#

  • Provider credentials are referenced by environment variable (*_env) or sealed with AES-256-GCM. An inline api_key on a write is discarded.
  • synapass config prints the resolved configuration with secrets redacted.
  • The gateway refuses to start on unsafe production configuration: a CORS wildcard, a missing admin key, or tracing with no OTLP endpoint.

Audit logging#

Every control-plane mutation is recorded with before and after values. Inference traffic is not audited — usage records serve that need, without duplicating prompt content into a second store.

Reporting vulnerabilities#

Do not open a public issue for a suspected vulnerability. Report it privately — see SECURITY.md in the repository, or reach us through the contact page. We treat key-material handling, auth bypass, tenant cross-talk, and denial-of-wallet as high severity.