Skip to main content
Version: 1.28 (Current)

Security

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

The Security actions protect data and manage security roles. They encrypt and decrypt values with AES or RSA, encrypt values in the format the connector store uses, and create, change and delete roles in the current portal.

To create RSA key pairs in PEM format or check a domain's DKIM record, use Generate RSA Keys and Verify DKIM DNS Record. They also appear in the Security group, but they're part of the Security add-on.

Choosing an action​

Encryption​

ActionWhat it doesUse it to
AES EncryptEncrypts values with a shared AES key and IV, and saves each result as base64 in a token.Encrypt a national ID or bank account number before saving it.
AES DecryptDecrypts AES values with the same key and IV.Decrypt a value you encrypted with AES Encrypt before you show it or send it on.
RSA EncryptEncrypts short values with an RSA public key.Encrypt a PIN or an AES key so only the holder of the private key can read it.
RSA DecryptDecrypts RSA values with the matching private key.Decrypt a value a partner system encrypted with your public key.
Connector EncryptEncrypts values with this installation's connector store key, in the format connectors store their values.Write or compare connector values in the database with SQL.

Roles​

ActionWhat it doesUse it to
Create RoleCreates a security role in the current portal and saves its ID in a token.Create a role for each new customer, team or project.
Update RoleChanges a role's name, description, group, status or options. Empty parameters keep their value.Rename a role, approve it, or move it to another role group.
Delete RoleDeletes a role. Users who had it lose it.Clean up roles for closed accounts or temporary projects.

To give a role to users or take it away, use Grant User Role and Revoke User Role from the User Management add-on.

Which encryption to use​

You need toUse
Encrypt and decrypt inside your own app, or with a partner that shares the secretAES Encrypt and AES Decrypt
Let others encrypt data that only you can decryptRSA Encrypt with the public key, RSA Decrypt with the private key
Encrypt long textAES. RSA only handles short values, for example up to 245 bytes with a 2048-bit key. To protect long data with RSA, encrypt it with AES and use RSA for the AES key.
Encrypt a value in the connector store's formatConnector Encrypt. No action decrypts these values. Connectors and the Connector Format grid formatter do.
  • Not for passwords. Encryption can be reversed. Passwords should be hashed, not encrypted.
  • No signing. The AES and RSA actions only encrypt. They can't prove a value came from you or wasn't changed. AES Encrypt also uses the same IV for every value, so equal values give equal results.
  • Errors differ. AES Encrypt saves an error message in the output token instead of failing. AES Decrypt, RSA Encrypt and RSA Decrypt fail the action. An empty key does nothing in all four. Check each page before relying on it.

Key formats​

The actions don't share one key format, so keys from one action don't always work in another:

  • AES Encrypt and AES Decrypt need a base64 key that decodes to 16, 24 or 32 bytes, and a base64 IV of 16 bytes. Create them with the key generator linked in the AES Key help text. A password such as MySecret won't work.
  • RSA Encrypt and RSA Decrypt need keys in .NET XML format, starting with <RSAKeyValue>. Create them with the key generator linked in their Public Key and Private Key help texts.
  • PEM keys don't work here. Generate RSA Keys, from the Security add-on, creates base64 and PEM keys, which RSA Encrypt and RSA Decrypt can't read. Use its keys for DKIM and for systems that expect PEM.
  • Connector Encrypt uses this installation's own key. You don't supply one, and another installation can't decrypt the values.

Load keys from tokens instead of typing them into the action, and keep them out of logs, emails and the browser. Add Connector stores values encrypted, and Get Connector reads them back into tokens. Use 2048-bit RSA keys or more.

Managing roles safely​

  • There's no permission check. Anyone who can run Create Role, Update Role or Delete Role can change any role in the portal. Only put them where administrators or other trusted users can reach them.
  • System roles aren't protected. Update Role and Delete Role also work on Administrators and Registered Users. Deleting them breaks the portal. Add a condition that blocks them.
  • Numbers are role IDs. A role identifier such as 2024 is always looked up as an ID, so avoid role names that are only numbers.
  • Set the status. Create Role creates a Disabled role when Role Status is empty or not recognized. Status names are case-sensitive, for example Approved.
  • Auto Assign reads Is Public. Because of a product bug, Create Role and Update Role use the value of Is Public for Auto Assign. See those pages before using either option, or Add to existing users.

For connectors and connector values, see the Connectors actions.

Revised 10/02/2026