The runtime today fails with 500 when keys are not decryptable and the user needs to manually go and clean them up. It'll be much better if for example 1. rename `<name>.json` to `<name>.json.undecryptable` 2. log message saying that happened. 3. create a new key