Skip to content
- Tenant isolation is PostgreSQL row-level security on every tenant table, driven by a session setting. Access without a tenant fails
closed. The host serves traffic as
stayfn_app (DML only, no RLS bypass) and migrates as stayfn_migrator.
- Tenants authenticate with API keys (
stayfn_ + 32 random characters). Keys are stored as SHA-256(pepper + key), shown once,
scoped (functions:invoke, functions:read, events:webhook), and can expire or be revoked.
- Admins authenticate with JWTs. The key is HS256 with a static key, or RS256 through
Auth:JwksUrl from an OIDC provider, which is
recommended for production. The roles are owner ⊇ operator ⊇ viewer. A request that carries both a JWT and an API key is refused.
Production identity provider: not chosen yet. Until one is configured, admin tokens come from stayfn dev token (Development) or
from HS256 tokens you mint with the production signing key.
- Secrets are references, resolved through
env:, AWS Secrets Manager, Vault or Azure Key Vault. They are never stored in the database
or returned by the API.
- HTTP hardening: CSP, HSTS outside Development,
nosniff, no-referrer and frame-ancestors 'none'; 1 MB body limits; load shedding.
- Supply chain: vulnerability audits and CycloneDX SBOMs in CI, pinned dependencies, and a licence allow-list.