Skip to content
VibeAdmin

Security

An admin tool holds the keys to your users, so it is built around least privilege. This is what is in place today, and what is not.

In place today

Least privilege

Integrations are read-only by default. Write access is opt-in per connection, and the permission screen lists exactly what VibeAdmin can do.

Encrypted credentials

Service-role keys and provider tokens are encrypted with AES-256-GCM using a key derived per project. They are never returned by the API after saving.

Isolated environments

Development, preview and production data are separate. A test key cannot read production and a live key cannot read development.

Scoped, hashed API keys

Keys carry explicit scopes, are stored as hashes, shown once, and can be rotated or revoked. Last-used times are tracked.

Roles and permissions

Owner, Admin, Support and Analyst roles map to permission sets, checked on the server for every action, including those taken by API keys and MCP.

Append-only audit log

Every mutation records who did what, when, from which IP, with before and after values. Secrets are redacted.

Platform hygiene

Rate limiting on the API, MCP and sign-in, CSRF origin checks, strict security headers including a content security policy, signed webhooks, and SSRF protection for outbound integration calls.

Safe AI access

MCP tools are hidden from keys without the scope, writes are audited, sending email needs confirmation, and the email-writing AI never receives user data.

Not built yet

Two-factor authentication for admins, suspicious-login detection, SSO/SAML and SCIM, an independent penetration test, and SOC 2 or similar certification. These are planned and should not be assumed.

Give your app the admin it forgot

Free for up to 500 users. Connect Supabase, push users with the API, or paste one prompt into your coding agent.