Security
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
The Security actions protect data and manage security roles. They encrypt and decrypt values with AES or RSA, encrypt values in the format the connector store uses, and create, change and delete roles in the current portal.
To create RSA key pairs in PEM format or check a domain's DKIM record, use Generate RSA Keys and Verify DKIM DNS Record. They also appear in the Security group, but they're part of the Security add-on.
Choosing an action
Encryption
| Action | What it does | Use it to |
|---|---|---|
| AES Encrypt | Encrypts values with a shared AES key and IV, and saves each result as base64 in a token. | Encrypt a national ID or bank account number before saving it. |
| AES Decrypt | Decrypts AES values with the same key and IV. | Decrypt a value you encrypted with AES Encrypt before you show it or send it on. |
| RSA Encrypt | Encrypts short values with an RSA public key. | Encrypt a PIN or an AES key so only the holder of the private key can read it. |
| RSA Decrypt | Decrypts RSA values with the matching private key. | Decrypt a value a partner system encrypted with your public key. |
| Connector Encrypt | Encrypts values with this installation's connector store key, in the format connectors store their values. | Write or compare connector values in the database with SQL. |
Roles
| Action | What it does | Use it to |
|---|---|---|
| Create Role | Creates a security role in the current portal and saves its ID in a token. | Create a role for each new customer, team or project. |
| Update Role | Changes a role's name, description, group, status or options. Empty parameters keep their value. | Rename a role, approve it, or move it to another role group. |
| Delete Role | Deletes a role. Users who had it lose it. | Clean up roles for closed accounts or temporary projects. |
To give a role to users or take it away, use Grant User Role and Revoke User Role from the User Management add-on.
Which encryption to use
| You need to | Use |
|---|---|
| Encrypt and decrypt inside your own app, or with a partner that shares the secret | AES Encrypt and AES Decrypt |
| Let others encrypt data that only you can decrypt | RSA Encrypt with the public key, RSA Decrypt with the private key |
| Encrypt long text | AES. RSA only handles short values, for example up to 245 bytes with a 2048-bit key. To protect long data with RSA, encrypt it with AES and use RSA for the AES key. |
| Encrypt a value in the connector store's format | Connector Encrypt. No action decrypts these values. Connectors and the Connector Format grid formatter do. |
- Not for passwords. Encryption can be reversed. Passwords should be hashed, not encrypted.
- No signing. The AES and RSA actions only encrypt. They can't prove a value came from you or wasn't changed. AES Encrypt also uses the same IV for every value, so equal values give equal results.
- Errors differ. AES Encrypt saves an error message in the output token instead of failing. AES Decrypt, RSA Encrypt and RSA Decrypt fail the action. An empty key does nothing in all four. Check each page before relying on it.
Key formats
The actions don't share one key format, so keys from one action don't always work in another:
- AES Encrypt and AES Decrypt need a base64 key that decodes to 16, 24 or 32 bytes, and a base64 IV of 16 bytes. Create them with the key generator linked in the AES Key help text. A password such as
MySecretwon't work. - RSA Encrypt and RSA Decrypt need keys in .NET XML format, starting with
<RSAKeyValue>. Create them with the key generator linked in their Public Key and Private Key help texts. - PEM keys don't work here. Generate RSA Keys, from the Security add-on, creates base64 and PEM keys, which RSA Encrypt and RSA Decrypt can't read. Use its keys for DKIM and for systems that expect PEM.
- Connector Encrypt uses this installation's own key. You don't supply one, and another installation can't decrypt the values.
Load keys from tokens instead of typing them into the action, and keep them out of logs, emails and the browser. Add Connector stores values encrypted, and Get Connector reads them back into tokens. Use 2048-bit RSA keys or more.
Managing roles safely
- There's no permission check. Anyone who can run Create Role, Update Role or Delete Role can change any role in the portal. Only put them where administrators or other trusted users can reach them.
- System roles aren't protected. Update Role and Delete Role also work on
AdministratorsandRegistered Users. Deleting them breaks the portal. Add a condition that blocks them. - Numbers are role IDs. A role identifier such as
2024is always looked up as an ID, so avoid role names that are only numbers. - Set the status. Create Role creates a
Disabledrole when Role Status is empty or not recognized. Status names are case-sensitive, for exampleApproved. - Auto Assign reads Is Public. Because of a product bug, Create Role and Update Role use the value of Is Public for Auto Assign. See those pages before using either option, or Add to existing users.
For connectors and connector values, see the Connectors actions.
Revised 10/02/2026