-
Notifications
You must be signed in to change notification settings - Fork 0
Encryption and Key Management
github-actions[bot] edited this page Sep 26, 2026
·
7 revisions
Jupiter needs one stable 256-bit master key for its database. Keep the same key whenever you start Jupiter against that database.
openssl rand -base64 32The value must be standard Base64 decoding to exactly 32 bytes.
Jupiter encrypts sensitive persisted values before storing them in SQLite. The key itself is kept out of normal agent, terminal, and MCP environments.
A wrong key causes startup failure. Losing the key makes encrypted data unrecoverable.
Back up the key separately from the SQLite database.
Docker accepts JUPITER_ENCRYPTION_KEY during startup, and passes the key into Jupiter after trusted initialization
scripts run.