How are provider credentials handled?
Vercel and Sentry tokens and Stripe restricted keys are validated against provider access before they are encrypted. Application logs must not include credentials, authorization headers, cookies, or raw provider payloads. Disconnecting removes stored credentials.
