# How Chat2DB Community Encrypts Datasource Passwords and API Keys: AES-256-GCM Explained

> Chat2DB Community secures passwords and API keys using AES-256-GCM encryption. Learn how this advanced method protects your data at rest, ensuring confidentiality and integrity.

- Repository: [OtterMind/Chat2DB](https://github.com/OtterMind/Chat2DB)
- Tags: best-practices
- Published: 2026-07-26

---

**Chat2DB Community uses AES-256-GCM encryption with a per-installation 256-bit key to secure datasource passwords and AI model API keys at rest, ensuring both confidentiality and integrity.**

Chat2DB Community is an open-source database management tool that handles sensitive credentials including database passwords and AI service API keys. Understanding how Chat2DB Community encrypts datasource passwords and API keys is essential for security-conscious users and contributors who want to verify the protection of their stored secrets. The implementation relies on standard Java cryptographic libraries and follows best practices for authenticated encryption.

## AES-256-GCM Encryption Architecture

The encryption system in Chat2DB Community is built around **AES-256-GCM** (Advanced Encryption Standard in Galois/Counter Mode with a 256-bit key). This algorithm provides both **confidentiality** and **authentication**, preventing unauthorized access and detecting tampering with encrypted values.

According to the source code in [`chat2db-community-server/chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java`](https://github.com/OtterMind/Chat2DB/blob/main/chat2db-community-server/chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java), the implementation uses the Java Cryptography Architecture transformation **`AES/GCM/NoPadding`**. The system employs distinct Additional Authenticated Data (AAD) strings for different secret types:

- **`DATASOURCE_PASSWORD_AAD`** for database credentials
- **`AI_MODEL_API_KEY_AAD`** for AI service API keys

## Per-Installation Encryption Key Management

Chat2DB Community generates a unique encryption key for each installation rather than using a hardcoded or shared key. The key management logic resides in [`CommunityEncryptionKeyStore.java`](https://github.com/OtterMind/Chat2DB/blob/main/CommunityEncryptionKeyStore.java).

When the application starts for the first time, it automatically generates a **32-byte random key** (256 bits) and persists it to `~/.config/chat2db-community/encryption.key`. Alternatively, users can supply a custom key via the `chat2db.community.encryption-key` property or an environment variable, allowing for key rotation or external key management integration.

The key store validates key length and format before use, ensuring that only properly sized 256-bit keys are loaded into the AES-GCM cipher.

## Core Encryption Utility Implementation

The `AesGcmUtil` class serves as the central cryptographic engine for the application. Located at [`chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java`](https://github.com/OtterMind/Chat2DB/blob/main/chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java), this utility provides three primary methods:

- **`encrypt(String data)`** – Encrypts datasource passwords using the datasource-specific AAD
- **`encryptAiModelApiKey(String data)`** – Encrypts AI model API keys using the AI-specific AAD  
- **`decrypt(String ciphertext)`** – Decrypts previously encrypted values regardless of type

The utility loads the per-installation key through the `configured()` factory method, which initializes the cipher with the 256-bit key stored by `CommunityEncryptionKeyStore`.

## Where Encryption Is Applied in the Codebase

Encryption is applied at the persistence layer before sensitive data reaches the storage backend.

### Datasource Password Protection

In [`LocalWorkspaceStorage.java`](https://github.com/OtterMind/Chat2DB/blob/main/LocalWorkspaceStorage.java) ([`chat2db-community-storage/src/main/java/ai/chat2db/community/storage/LocalWorkspaceStorage.java`](https://github.com/OtterMind/Chat2DB/blob/main/chat2db-community-storage/src/main/java/ai/chat2db/community/storage/LocalWorkspaceStorage.java)), datasource passwords are encrypted before saving. Around lines 240-244, the storage layer calls an internal `encryptString` method that delegates to `AesGcmUtil.configured().encrypt(password)`, ensuring that database credentials never persist in plaintext.

### AI Model API Key Protection

For AI service integrations, [`AiModelConfigServiceImpl.java`](https://github.com/OtterMind/Chat2DB/blob/main/AiModelConfigServiceImpl.java) ([`chat2db-community-domain/chat2db-community-domain-core/src/main/java/ai/chat2db/community/domain/core/impl/ai/AiModelConfigServiceImpl.java`](https://github.com/OtterMind/Chat2DB/blob/main/chat2db-community-domain/chat2db-community-domain-core/src/main/java/ai/chat2db/community/domain/core/impl/ai/AiModelConfigServiceImpl.java)) handles API key encryption. At line 407, the service invokes `aesGcmUtil.encryptAiModelApiKey(apiKey)` when storing configuration, and uses the corresponding decrypt method when retrieving credentials for AI model calls.

## Practical Code Examples

The following examples demonstrate how the encryption system works within the Chat2DB Community codebase:

```java
// Encrypting a datasource password
AesGcmUtil aes = AesGcmUtil.configured();      // Loads the per-installation key
String encryptedPwd = aes.encrypt("mySecretPassword");

```

```java
// Encrypting an AI model API key
String encryptedKey = aes.encryptAiModelApiKey("sk-abcdef1234567890");

```

```java
// Decrypting stored values (used internally when reading credentials)
String plainPassword = aes.decrypt(encryptedPwd);
String plainApiKey = aes.decrypt(encryptedKey);

```

```java
// Implementation pattern from LocalWorkspaceStorage
private String encryptString(String value) {
    return AesGcmUtil.configured().encrypt(value);
}

// Applied when persisting datasource configuration
dataSource.setPassword(encryptString(dataSource.getPassword()));

```

## Summary

- Chat2DB Community protects sensitive data using **AES-256-GCM** authenticated encryption via the Java Cryptography Architecture.
- A **unique 256-bit key** is generated per installation and stored in `~/.config/chat2db-community/encryption.key`, with support for custom keys via the `chat2db.community.encryption-key` property.
- The **`AesGcmUtil`** class in `chat2db-community-tools` provides centralized encryption and decryption methods with distinct AAD strings for datasource passwords and AI API keys.
- Encryption occurs in **[`LocalWorkspaceStorage.java`](https://github.com/OtterMind/Chat2DB/blob/main/LocalWorkspaceStorage.java)** for database credentials and **[`AiModelConfigServiceImpl.java`](https://github.com/OtterMind/Chat2DB/blob/main/AiModelConfigServiceImpl.java)** for AI model keys, ensuring plaintext secrets never persist to disk.

## Frequently Asked Questions

### What encryption algorithm does Chat2DB Community use for stored passwords?

Chat2DB Community uses **AES-256-GCM** (Advanced Encryption Standard with Galois/Counter Mode). This provides both encryption and authentication, ensuring that stored datasource passwords and API keys cannot be read or tampered with without the per-installation encryption key.

### Where is the encryption key stored in Chat2DB Community?

The encryption key is stored in a file at `~/.config/chat2db-community/encryption.key` by default. The `CommunityEncryptionKeyStore` class manages this location, though users can override the key via the `chat2db.community.encryption-key` system property or environment variable for centralized key management.

### Can I use my own encryption key with Chat2DB Community?

Yes. While Chat2DB Community automatically generates a random 32-byte key on first startup, you can supply your own 256-bit key through the `chat2db.community.encryption-key` configuration property. This allows integration with external key management systems or enterprise key rotation policies.

### Does Chat2DB Community encrypt AI model API keys differently from database passwords?

Both use the same AES-256-GCM algorithm, but with different Additional Authenticated Data (AAD) strings. The system uses `DATASOURCE_PASSWORD_AAD` for database credentials and `AI_MODEL_API_KEY_AAD` for AI service keys. This separation ensures that ciphertexts from one type cannot be substituted for the other without detection.