Credential security
Understand how Durin and provider credentials stay separate.
Separate authentication boundaries
Your client authenticates to Durin. Upstream requests use the configured provider credential, bound to the tenant, identity, provider, scopes, environment, and intended audience. Durin does not pass its own bearer token to the upstream provider.
Keep secrets out of diagnostics
Use request IDs, connection IDs, timestamps, and error messages when investigating access. Do not paste provider tokens or secret configuration into support messages. An issued endpoint URL identifies an entry point; it does not replace authentication.
Frequently asked questions
Does disconnecting my provider disable it for everyone?
No. Personal disconnect affects your access. An administrator uses Disable installation to stop normal routing for the workspace.
Does adding Durin revoke credentials used elsewhere?
No. Your team must separately manage other client endpoints, direct provider credentials, and network controls.