New — Sohay now answers WooCommerce product, policy & cart questions. See how →

Where your API keys are stored

Encrypted at rest in your own database, masked in the admin, excluded from the REST API, and never readable back.

Your API keys live in your own WordPress database, and nowhere else. Sohay does not proxy them through any service of ours, because there is no service of ours.

The guarantees

  • Encrypted at rest with AES-256-GCM in the options table.
  • Masked in the admin. Once saved, the field shows a placeholder. The real value is never rendered back into a page.
  • Excluded from the WordPress REST API, so no authenticated endpoint returns them.
  • Sent only to the service they belong to. An OpenAI key is never included in a request to Google, or the reverse.

The consequence

Sohay is not somewhere to look a key up. There is no reveal button, and adding one would undo the point of the masking.

Keep your own copy in a password manager. If you lose it, revoke it at the provider and issue a new one — that is faster than any recovery would be, and safer.

Saving a key for a provider you are not using

Supported, and useful. It is stored but never sent anywhere, and it is what makes switching providers instant later.

If you use the Knowledge Base, an OpenAI key is required regardless of which provider answers the chat. See Choosing between OpenAI and Google Gemini.

Replacing or removing one

To replace, paste the new key over the placeholder and save.

To stop using a provider, clear the field and save — then revoke the key at the provider. Clearing it here stops Sohay using it; only the provider can actually invalidate it. If a key has been exposed, revoking is the step that matters and clearing the field is not a substitute.

Who can see the settings screen

Reaching AI Settings requires the sohaychat_manage capability, which administrators hold. That is the capability to be careful with: it covers provider selection, key entry, and model choice.

Somebody who only needs to read and reply to conversations does not need it, and should not have it. See Giving your team access without making them admins.

What this does not protect against

Encryption at rest protects the value in your database. It does not protect against somebody with administrator access to your WordPress site, or shell access to your server — such a person can reach whatever the site can reach.

The practical defences are the ordinary ones: few administrators, strong authentication, and a spending cap at the provider so a leaked key has a bounded cost. Daily token caps and rate limits covers the caps Sohay itself enforces.

Where to go next

What Sohay sends to OpenAI and Google for what the keys are used to send.

Mithun B.
Mithun B.

More articles by Mithun B..

View all posts

Give your website an assistant that answers from your content

Grounded answers, a team inbox, and store-aware tools — free on WordPress.org.

Add Sohay — Free

Free plugin · You bring your OpenAI key · Works with any theme