From abea93771a66879bb16021bd8c8a1c11201acdab Mon Sep 17 00:00:00 2001 From: Santhosh Kumar Bala Krishnan Date: Fri, 25 Sep 2026 13:51:41 +0000 Subject: [PATCH] IGA-4417: document encrypted (JWE) credential issuance Rebased onto current main. baton-admin has since synced main to baton-sdk v0.33.0, which already vendors the baton/jwe/v1 provider and advertises CAPABILITY_CREDENTIAL_ENCRYPTION_JWE_XWING_V1 for this connector, so the SDK-side changes this branch originally carried are identical to upstream and are dropped here. What remains is the docs note: issued Datadog application keys can be returned encrypted to a recipient key that C1 supplies. Co-authored-by: c1-squire-dev[bot] --- docs/connector.mdx | 2 ++ 1 file changed, 2 insertions(+) diff --git a/docs/connector.mdx b/docs/connector.mdx index b89385fe..4c6cac88 100644 --- a/docs/connector.mdx +++ b/docs/connector.mdx @@ -25,6 +25,8 @@ sidebarTitle: "Datadog" An application key can be issued and revoked through C1 when **Sync secrets** and **Sync service account application keys** are both enabled, provided the selected Datadog user is a service account. Datadog does not support an expiration date when creating an application key. +Issued keys can be returned encrypted to a recipient key that C1 supplies, so the plaintext key never leaves the connector unencrypted. + Credential issuance targets a Datadog service account only. C1 re-checks at issuance time that the selected user is still a service account, and refuses to issue against a human user. The issued application key is owned by, and scoped to, that service account.