AGE Encryption
Reference for the encryption that protects keys and passwords in your config file. Plain-language introduction: Config Security with AGE. Step by step: Sandbox and permissions.
Pando uses AGE.
- Values that start with
age1:are decrypted when the config is loaded. - Decrypted values stay in memory only.
- A key pair (X25519) is created the first time one is needed.
Commands
pando secret my-token # encrypt: prints age1:…
pando secret 'age1:YWdlLWVu...' # decrypt: prints the original
pando secret my-token --age-keys mykeys # use a named key setpando secret detects the direction by itself: a plain value is encrypted, an age1: value is decrypted. --age-keys works on every Pando command.
Configuration
AgeKeys = '' # named key set; empty means "default"What is encrypted
- Provider API keys (
[providers.*].apiKey) - OAuth tokens (
[providers.*].accessToken,refreshToken) - MCP server environment variables (
[mcpServers.*].env.*) - Embedding API keys
- Web UI passwords
- Any value you prefix with
age1:
Where the keys are
~/.config/pando/keys/
default/
key.txt # private key
public.txt # public key
mykeys/
key.txt
public.txtThe private key never leaves your machine. A config file with
age1: values can only be opened where that key is, so a teammate or another computer needs their own keys or a copy of yours.