Ext Probe

Security Overview

This page summarizes how Ext Probe currently handles tokens, permissions, revocation, and audit visibility.

Last updated: 2026-06-14

Security Principles

  1. Request only the scopes needed for monitoring workflows.
  2. Keep token secret material out of normal frontend workspace responses.
  3. Encrypt marketplace tokens before storage.
  4. Give users a clear disconnect and revoke-at-source path.
  5. Record audit events without exposing secrets in normal trust views.

Current Token Handling

Storage Model

Extension Permissions

Disconnect And Revocation

Audit Visibility

Ext Probe exposes a trust status view that summarizes vault mode, storage mode, and recent audit activity without returning token secret material. Audit events help explain successful auth, disconnect, alert delivery, and revoke-related actions.

Current Limits