Skip to content

Security model

  • Tenant isolation is PostgreSQL row-level security on every tenant table, driven by a session setting. Access without a tenant fails closed. The host serves traffic as stayfn_app (DML only, no RLS bypass) and migrates as stayfn_migrator.
  • Tenants authenticate with API keys (stayfn_ + 32 random characters). Keys are stored as SHA-256(pepper + key), shown once, scoped (functions:invoke, functions:read, events:webhook), and can expire or be revoked.
  • Admins authenticate with JWTs. The key is HS256 with a static key, or RS256 through Auth:JwksUrl from an OIDC provider, which is recommended for production. The roles are owner ⊇ operator ⊇ viewer. A request that carries both a JWT and an API key is refused. Production identity provider: not chosen yet. Until one is configured, admin tokens come from stayfn dev token (Development) or from HS256 tokens you mint with the production signing key.
  • Secrets are references, resolved through env:, AWS Secrets Manager, Vault or Azure Key Vault. They are never stored in the database or returned by the API.
  • HTTP hardening: CSP, HSTS outside Development, nosniff, no-referrer and frame-ancestors 'none'; 1 MB body limits; load shedding.
  • Supply chain: vulnerability audits and CycloneDX SBOMs in CI, pinned dependencies, and a licence allow-list.