megachangelog
Feature

End-to-end encryption for Vercel Workflow

Vercel Workflow now automatically encrypts all user data end-to-end, including inputs, arguments, return values, and payloads, without requiring code changes. Sensitive data like API keys and credentials are securely encrypted before storage in the event log, with decryption available on-demand through the dashboard or CLI while maintaining permission controls.

Vercel Workflow now encrypts all user data end-to-end without requiring any code changes. Workflow inputs, step arguments, return values, hook payloads, and stream data are automatically encrypted before being written to the event log.

This makes it safe to pass sensitive data, such as API keys, tokens, or user credentials, across boundaries. The event log only ever stores ciphertext, while your step functions work exactly as before.

Your workflow and step functions work exactly as before; all data flowing through the event log is encrypted automatically.

Each Vercel deployment receives a unique encryption key. The key derivation and encryption stack works as follows:

You can access encrypted data through two methods:

: Click the Decrypt button in the run detail panel. Decryption happens entirely in the browser via the Web Crypto API, so the observability server never sees your plaintext data. Add the flag to the command.Web dashboardCLI:--decryptinspect

Decryption follows the same permissions model as project environment variables, meaning you cannot access workflow data if you lack permission to view environment variables. Each decryption request is recorded in your Vercel , providing your team with full visibility into access events.audit log

While end-to-end encryption is built into the Vercel platform, custom implementations can opt into this feature. You can provide your own method, which the core runtime uses automatically. Learn more in the .WorldgetEncryptionKeyForRun()Workflow DevKit documentation

Read more

  • Each workflow run derives its own key via HKDF-SHA256

  • Data is encrypted with AES-256-GCM to ensure confidentiality and integrity

  • Encrypted fields display as locked placeholders in the dashboard until decrypted

securityencryptionworkflowprivacydata-protection

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →