Connector Encrypt
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens,SQL,Connectors
Encrypts one or more values the same way connectors encrypt their property values, and saves each result in a token. You don't supply a key. The action uses the connector store's own key for this installation.
Plant an App stores every connector property value encrypted in the DnnSharp_CredentialStoreData table. This action gives you a value in that same format, for example to write or compare connector values with SQL.
Typical Use Cases
- Write a connector property value directly to the
DnnSharp_CredentialStoreDatatable with Run SQL Query, for example in a bulk import - Find a stored connector value that equals a known value, by encrypting the known value and comparing the results in SQL
Don't use it to
- Create or change connectors. Use Add Connector or Update Connector instead. They encrypt the values for you.
- Encrypt your own app data. Use AES Encrypt or RSA Encrypt, where you control the key.
- Encrypt data you'll send outside this installation. Only this installation can decrypt it.
Related Actions
| Action Name | Description |
|---|---|
| Add Connector | Creates a connector. Its values are encrypted the same way. |
| Update Connector | Changes a connector's values. |
| Get Connector | Reads a connector and returns its values decrypted, with secure values masked. |
| AES Encrypt | Encrypts values with your own AES key and IV. |
| RSA Encrypt | Encrypts short values with a public key. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| Values to Encrypt | A list of values to encrypt. In Values, enter the value, usually a token such as [ApiKey]. In Output Token Names, enter the name of the token that gets the encrypted result, such as ApiKeyEncrypted. Square brackets around the name are removed. | Yes, in Values | empty | Yes |
Output Parameters Reference
| Token | Description |
|---|---|
[<Output Token Name>] | One token for each row in Values to Encrypt, holding the encrypted value as a base64 string. |
How it's encrypted
Values are encrypted with AES, using a key that belongs to this installation, and the result is base64. The same value always gives the same result on one installation, which is what makes comparing values in SQL possible.
Decrypting the result
There's no action that decrypts these values. AES Decrypt can't do it, because it expects a key and IV you supply, not the connector store's key. These values are decrypted:
- by the connector store, when the value is saved as a connector property, so actions that use the connector get the plain value, and Get Connector returns it (masked as
******for secure properties) - by the Connector Format formatter, which shows the decrypted value in a grid column
Considerations
- An empty value isn't empty. An empty input still gives a short encrypted string. Connectors themselves store an empty value as empty. Don't write the encrypted empty string to the table if you want the property to be blank.
- It only works on this installation. Another installation uses a different key, so it can't decrypt the values. Encrypt again after moving data.
- Equal values look equal. Anyone who can read the table can see which connectors share the same value, even without decrypting them.
- Protect database access and backups. Treat the connector table as sensitive, and limit who can read the database and its backups.
- Connector data is cached. Plant an App caches connector values, so a value you write with SQL may not be used until the cache is cleared.
- Don't log the input. The values you encrypt are usually secrets. Keep them out of debug logs.
Examples
To understand how to use the below examples, please see Running Examples.
1. Encrypt an API key for a connector import
This action encrypts [ApiKey] and saves the result in [ApiKeyEncrypted]. A later Run SQL Query action can write it to the DataValue column of DnnSharp_CredentialStoreData.
{
"Title": "Connector Encrypt",
"ActionType": "CredStore.EncryptValue",
"Description": "Encrypt the API key for the connector table",
"Condition": "[ApiKey] != \"\"",
"Parameters": {
"ValuesToEncrypt": {
"[ApiKey]": "ApiKeyEncrypted"
}
}
}
Revised 09/27/2026