How Chat2DB Community Encrypts Datasource Passwords and API Keys: AES-256-GCM Explained

Chat2DB Community uses AES-256-GCM encryption with a per-installation 256-bit key to secure datasource passwords and AI model API keys at rest, ensuring both confidentiality and integrity.

Chat2DB Community is an open-source database management tool that handles sensitive credentials including database passwords and AI service API keys. Understanding how Chat2DB Community encrypts datasource passwords and API keys is essential for security-conscious users and contributors who want to verify the protection of their stored secrets. The implementation relies on standard Java cryptographic libraries and follows best practices for authenticated encryption.

AES-256-GCM Encryption Architecture

The encryption system in Chat2DB Community is built around AES-256-GCM (Advanced Encryption Standard in Galois/Counter Mode with a 256-bit key). This algorithm provides both confidentiality and authentication, preventing unauthorized access and detecting tampering with encrypted values.

According to the source code in chat2db-community-server/chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java, the implementation uses the Java Cryptography Architecture transformation AES/GCM/NoPadding. The system employs distinct Additional Authenticated Data (AAD) strings for different secret types:

  • DATASOURCE_PASSWORD_AAD for database credentials
  • AI_MODEL_API_KEY_AAD for AI service API keys

Per-Installation Encryption Key Management

Chat2DB Community generates a unique encryption key for each installation rather than using a hardcoded or shared key. The key management logic resides in CommunityEncryptionKeyStore.java.

When the application starts for the first time, it automatically generates a 32-byte random key (256 bits) and persists it to ~/.config/chat2db-community/encryption.key. Alternatively, users can supply a custom key via the chat2db.community.encryption-key property or an environment variable, allowing for key rotation or external key management integration.

The key store validates key length and format before use, ensuring that only properly sized 256-bit keys are loaded into the AES-GCM cipher.

Core Encryption Utility Implementation

The AesGcmUtil class serves as the central cryptographic engine for the application. Located at chat2db-community-tools/src/main/java/ai/chat2db/community/tools/security/AesGcmUtil.java, this utility provides three primary methods:

  • encrypt(String data) – Encrypts datasource passwords using the datasource-specific AAD
  • encryptAiModelApiKey(String data) – Encrypts AI model API keys using the AI-specific AAD
  • decrypt(String ciphertext) – Decrypts previously encrypted values regardless of type

The utility loads the per-installation key through the configured() factory method, which initializes the cipher with the 256-bit key stored by CommunityEncryptionKeyStore.

Where Encryption Is Applied in the Codebase

Encryption is applied at the persistence layer before sensitive data reaches the storage backend.

Datasource Password Protection

In LocalWorkspaceStorage.java (chat2db-community-storage/src/main/java/ai/chat2db/community/storage/LocalWorkspaceStorage.java), datasource passwords are encrypted before saving. Around lines 240-244, the storage layer calls an internal encryptString method that delegates to AesGcmUtil.configured().encrypt(password), ensuring that database credentials never persist in plaintext.

AI Model API Key Protection

For AI service integrations, AiModelConfigServiceImpl.java (chat2db-community-domain/chat2db-community-domain-core/src/main/java/ai/chat2db/community/domain/core/impl/ai/AiModelConfigServiceImpl.java) handles API key encryption. At line 407, the service invokes aesGcmUtil.encryptAiModelApiKey(apiKey) when storing configuration, and uses the corresponding decrypt method when retrieving credentials for AI model calls.

Practical Code Examples

The following examples demonstrate how the encryption system works within the Chat2DB Community codebase:

// Encrypting a datasource password
AesGcmUtil aes = AesGcmUtil.configured();      // Loads the per-installation key
String encryptedPwd = aes.encrypt("mySecretPassword");
// Encrypting an AI model API key
String encryptedKey = aes.encryptAiModelApiKey("sk-abcdef1234567890");
// Decrypting stored values (used internally when reading credentials)
String plainPassword = aes.decrypt(encryptedPwd);
String plainApiKey = aes.decrypt(encryptedKey);
// Implementation pattern from LocalWorkspaceStorage
private String encryptString(String value) {
    return AesGcmUtil.configured().encrypt(value);
}

// Applied when persisting datasource configuration
dataSource.setPassword(encryptString(dataSource.getPassword()));

Summary

  • Chat2DB Community protects sensitive data using AES-256-GCM authenticated encryption via the Java Cryptography Architecture.
  • A unique 256-bit key is generated per installation and stored in ~/.config/chat2db-community/encryption.key, with support for custom keys via the chat2db.community.encryption-key property.
  • The AesGcmUtil class in chat2db-community-tools provides centralized encryption and decryption methods with distinct AAD strings for datasource passwords and AI API keys.
  • Encryption occurs in LocalWorkspaceStorage.java for database credentials and AiModelConfigServiceImpl.java for AI model keys, ensuring plaintext secrets never persist to disk.

Frequently Asked Questions

What encryption algorithm does Chat2DB Community use for stored passwords?

Chat2DB Community uses AES-256-GCM (Advanced Encryption Standard with Galois/Counter Mode). This provides both encryption and authentication, ensuring that stored datasource passwords and API keys cannot be read or tampered with without the per-installation encryption key.

Where is the encryption key stored in Chat2DB Community?

The encryption key is stored in a file at ~/.config/chat2db-community/encryption.key by default. The CommunityEncryptionKeyStore class manages this location, though users can override the key via the chat2db.community.encryption-key system property or environment variable for centralized key management.

Can I use my own encryption key with Chat2DB Community?

Yes. While Chat2DB Community automatically generates a random 32-byte key on first startup, you can supply your own 256-bit key through the chat2db.community.encryption-key configuration property. This allows integration with external key management systems or enterprise key rotation policies.

Does Chat2DB Community encrypt AI model API keys differently from database passwords?

Both use the same AES-256-GCM algorithm, but with different Additional Authenticated Data (AAD) strings. The system uses DATASOURCE_PASSWORD_AAD for database credentials and AI_MODEL_API_KEY_AAD for AI service keys. This separation ensures that ciphertexts from one type cannot be substituted for the other without detection.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →