Security model
Keys, session tokens, host JWTs, secret storage, tool guard rails and what the model provider sees.
Credentials
| Credential | Who holds it | Lifetime | Notes |
|---|---|---|---|
Publishable key kl_pub_… | The app | Until revoked | Opens sessions. Safe to ship; it cannot read data or change configuration. Stored hashed (SHA-256) server side. |
Secret key kl_sec_… | Your servers | Until revoked | Notifications, management. Never in client code. Stored hashed. |
Session token kst_… | The app, in memory | Short; refreshed by the SDK | Ed25519-signed by the runtime. Revocation is checked on every request. |
| Host JWT | Issued by your backend, passed to the SDK | Whatever you set | Verified with the HS256 secret or the JWKS URL you configure. |
| Dashboard session | Browser cookie | 30 days | Email one-time code (10-minute validity, 5 attempts), HMAC-signed cookie, address allowlist plus workspace membership. |
Secrets vault
Model keys, tool credentials and push service accounts are project secrets. They are encrypted with envelope encryption: a per-organisation data key encrypts each value with AES-GCM and additional authenticated data bound to the organisation and secret id; the data key is wrapped by a key-encryption key that exists only as a Worker secret. Dashboard members see names and last-used times, never values. Agents and tools reference secrets by name.
Tool guard rails
- Arguments are validated against the tool’s JSON schema before any request is made.
- The SSRF guard allows http and https only, refuses credentials in URLs and private, loopback, link-local and metadata hosts, and does not follow redirects at all.
- Every call has a timeout and is logged with status and latency.
- Act as user forwards the verified end-user identity, so your API decides permissions.
- Require confirmation pauses the turn until the user approves in the chat.
- The model can only render component types on the agent’s allowlist and can only open URLs on the URL allowlist.
Isolation
- Each conversation is its own Durable Object with its own SQLite log. No cross-conversation reads.
- Sessions carry organisation, project, environment, end user and agent. Every
/v1request is scoped by them. - Rate limits: 30 user messages per minute per end user by default, enforced in the project’s tenant object.
What the model provider receives
The rendered system prompt, the last N messages, tool specifications, tool results and the current user message. Kletso does not train on your data and does not share it between customers. Use sensitive context keys to keep values out of prompts.
Jev (beta). For judgments Kletso also sends the user’s latest message, the previous assistant text and a compact copy of the UI last shown to TypeSafe’s API, on Kletso’s own key. TypeSafe does not train on requests. Sensitive context keys are never included. Per-agent switch: Behaviour → Jev turn judgments.
Dashboard access
Sign-in is by email code to an allowlisted address that also has a workspace membership. Roles are owner, admin, developer and viewer. Developers and above edit agents, tools, workflows, triggers and components, and add or rotate secrets (never read them). Owners and admins manage API keys, webhooks, settings and members. Only owners change roles. Viewers read everything. A membership can be scoped to specific projects, so an outside collaborator sees only their project. Invite members from Settings → Organization.
Reporting
Security issues: security@kletso.ai. Please include reproduction steps; we acknowledge within two business days.