authType when registering a plugin — you do not pass tokens or secrets in your application code. Corsair stores credentials encrypted and retrieves the right ones for each tenant at request time.
Check each plugin’s overview page to see which auth types it supports and follow its setup steps.
corsair.ts
Auth types
Not every plugin supports every mode. Open the plugin’s docs — for example Slack or Linear — and use the Choose authentication section as the source of truth.Managed OAuth
Corsair hosts the OAuth app, so you register nothing in the provider console. SetauthType: "managed" and tenants connect through Hub.
OAuth 2.0
For integrations where you bring your own OAuth app. SetauthType: "oauth_2" in your plugin config, then enter the client ID and client secret in the Hub dashboard — not in corsair.ts or environment variables. Tenants authorize their accounts through Hub’s connect flow.
API key
For integrations that use static API keys or personal access tokens. At the plugin level you only declare the auth type (or omit it whenapi_key is the default). Each tenant supplies their own key during onboarding or on first use — keys are stored encrypted per tenant, not configured once for the whole plugin.
withTenant.
Bot token
Some plugins accept a bot or app-user token instead of a user API key. Like API keys, bot tokens are tenant-level: each tenant provides their own token when connecting. Check the plugin’s docs for the exact field name and setup flow.Automatic token refresh
When using OAuth, tokens expire. Corsair handles this automatically:- Before making a request, checks if the token is expired
- If expired, uses the refresh token to get a new access token
- Stores the new token and continues with the request
Envelope encryption
Corsair uses envelope encryption to protect credentials:- You set one KEK (Key Encryption Key) in your environment variables
- Each connection gets its own DEK (Data Encryption Key)
- All credentials are encrypted with the connection’s DEK
- The DEK is encrypted with your KEK
.env
This holds whether you self-host or use Hub. Hub is a relay for connect, approval, and webhook surfaces; it stores none of your tenants’ tokens. Encrypted tokens are persisted only in your database in both modes.
Multi-tenant credentials
With multi-tenancy, each tenant has their own credentials stored securely.example.ts