Security
What 0bridge can and can't read, and how your logins and keys are kept.
What the server can read#
- Service logins. The OAuth tokens and API keys of services you connect are stored encrypted, with a key per user, and used only to call those services for you. The server has to read them to make the calls.
- Conversation history, if you turn it on (
0b history on), so your coding agents can search it. With0b history mode e2eit's sealed with your vault key and only your machines can search it. - Clipboard items you send, until an agent reads them or 10 minutes pass.
- Activity, briefly. The audit log keeps sign-ins, changes to tokens, connections and secrets, and each tool call's name, result and time (with a short error message when a call fails); not what was sent or what came back. It's deleted after 90 days; encrypted backups can hold it up to 12 weeks longer.
What it can't read#
- Secrets in your vault. They're encrypted on your machine (AES-256-GCM) with a key only your devices hold; the server keeps ciphertext, plus the names so it can list them. Each value is bound to its name, scope and environment, so it can't be swapped for another.
- Personal files, sealed with the same vault key (their paths and sizes aren't).
Your agents and your secrets#
0b exechands values to a command as environment variables. When an agent reads the output, values show as***.- An agent that deliberately prints its environment can still see them. Masking protects against accidents, not against a command written to leak.
- Production values reach a machine only after you approve that machine in your browser, with your passkey (or a new email code if you have none), for 30 minutes, 2 hours or 8 hours. They're never kept in an offline copy.
Signing in#
- Sign in with an email code, Google or GitHub. Add a passkey under Settings.
- Approving a new device, giving an app access and creating a token need a sign-in from the last 10 minutes, with your passkey if you have one. Adding or removing a passkey needs your passkey when you already have one.
- Each machine gets its own token. The server keeps only a hash of it, signing out revokes it, and Settings → Devices revokes any of them.
- Recovery codes (ten, each used once) replace a lost passkey.
claude.ai, ChatGPT and other apps#
- Apps connect with OAuth 2.1 and PKCE. The consent screen shows the app and where it sends you back to, and their tokens only work for your 0bridge endpoint.
- Apps can call your tools; they can't change your vault.
- Remove an app in the app itself: claude.ai and ChatGPT. Its access tokens expire within an hour.
What we're still working on#
- A machine's token can do most of what your account can; it can't create other tokens or use production values without your approval. Narrower tokens (read-only, per service) are planned. A project's token only opens that project.
- Revoking claude.ai's or ChatGPT's access from the dashboard isn't there yet; remove it in the app.
- Tool descriptions from the services you connect reach your agent as those services wrote them. Treat an unfamiliar MCP server like any code you'd run.
Report a problem#
Write to support@0bridge.dev. Security reports get an answer first.