← All posts

Why we never store your API keys

StackClock team ·

To remind you that a key needs rotating, we need to know when, who and where to rotate it. We do not need the key.

Metadata only

For API keys, licenses and subscriptions StackClock stores a name, the provider, the expiry date, an owner and a link to the rotation page. Nothing else.

Rejecting pasted secrets

People paste secrets into the wrong field. So every free-text field for these assets is checked against the formats of common credentials (cloud provider keys, payment keys, tokens, private keys) and high-entropy strings. A match is refused with a clear message, before anything is saved.

Defense in depth

Even data we do keep is isolated per workspace by the database itself, so one customer can never read another's rows, even if application code has a bug. You can read more on our security page.