Security

Security

Local-first credential security and a strict cloud boundary.

Credentials stay local

The commercial backend does not require Codex auth.json, access tokens, refresh tokens, projects, MCPs, or Skills.

Vault protection

AES-256-GCM protects stored credential material, with a random vault key protected by Windows DPAPI CurrentUser.

Recovery

Account activation is designed around validation, atomic writes, verification, and rollback.

cloud: license ✓
cloud: device ✓
cloud: purchase ✓

cloud: Codex tokens ✕
cloud: auth.json ✕
cloud: projects ✕