Skip to main content
Version: 1.28 (Current)

Connector Encrypt

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, SQL, Connectors

Encrypts one or more values the same way connectors encrypt their property values, and saves each result in a token. You don't supply a key. The action uses the connector store's own key for this installation.

Plant an App stores every connector property value encrypted in the DnnSharp_CredentialStoreData table. This action gives you a value in that same format, for example to write or compare connector values with SQL.

Typical Use Cases​

  • Write a connector property value directly to the DnnSharp_CredentialStoreData table with Run SQL Query, for example in a bulk import
  • Find a stored connector value that equals a known value, by encrypting the known value and comparing the results in SQL

Don't use it to​

  • Create or change connectors. Use Add Connector or Update Connector instead. They encrypt the values for you.
  • Encrypt your own app data. Use AES Encrypt or RSA Encrypt, where you control the key.
  • Encrypt data you'll send outside this installation. Only this installation can decrypt it.
Action NameDescription
Add ConnectorCreates a connector. Its values are encrypted the same way.
Update ConnectorChanges a connector's values.
Get ConnectorReads a connector and returns its values decrypted, with secure values masked.
AES EncryptEncrypts values with your own AES key and IV.
RSA EncryptEncrypts short values with a public key.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
Values to EncryptA list of values to encrypt. In Values, enter the value, usually a token such as [ApiKey]. In Output Token Names, enter the name of the token that gets the encrypted result, such as ApiKeyEncrypted. Square brackets around the name are removed.Yes, in ValuesemptyYes

Output Parameters Reference​

TokenDescription
[<Output Token Name>]One token for each row in Values to Encrypt, holding the encrypted value as a base64 string.

How it's encrypted​

Values are encrypted with AES, using a key that belongs to this installation, and the result is base64. The same value always gives the same result on one installation, which is what makes comparing values in SQL possible.

Decrypting the result​

There's no action that decrypts these values. AES Decrypt can't do it, because it expects a key and IV you supply, not the connector store's key. These values are decrypted:

  • by the connector store, when the value is saved as a connector property, so actions that use the connector get the plain value, and Get Connector returns it (masked as ****** for secure properties)
  • by the Connector Format formatter, which shows the decrypted value in a grid column

Considerations​

  • An empty value isn't empty. An empty input still gives a short encrypted string. Connectors themselves store an empty value as empty. Don't write the encrypted empty string to the table if you want the property to be blank.
  • It only works on this installation. Another installation uses a different key, so it can't decrypt the values. Encrypt again after moving data.
  • Equal values look equal. Anyone who can read the table can see which connectors share the same value, even without decrypting them.
  • Protect database access and backups. Treat the connector table as sensitive, and limit who can read the database and its backups.
  • Connector data is cached. Plant an App caches connector values, so a value you write with SQL may not be used until the cache is cleared.
  • Don't log the input. The values you encrypt are usually secrets. Keep them out of debug logs.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Encrypt an API key for a connector import​

This action encrypts [ApiKey] and saves the result in [ApiKeyEncrypted]. A later Run SQL Query action can write it to the DataValue column of DnnSharp_CredentialStoreData.

{
"Title": "Connector Encrypt",
"ActionType": "CredStore.EncryptValue",
"Description": "Encrypt the API key for the connector table",
"Condition": "[ApiKey] != \"\"",
"Parameters": {
"ValuesToEncrypt": {
"[ApiKey]": "ApiKeyEncrypted"
}
}
}

Revised 09/27/2026