Identity and sessions
Google and Microsoft OpenID Connect use state, nonce, and PKCE validation. Relay stores revocable hashed sessions, not identity-provider passwords.
Relay is designed around scoped identity, separated organizations, revocable connections, explicit permissions, human approval, and visible activity.
Google and Microsoft OpenID Connect use state, nonce, and PKCE validation. Relay stores revocable hashed sessions, not identity-provider passwords.
Each active session is pinned to one organization. Membership and permissions are checked before organization data is read or changed.
Provider credentials and application secrets remain server-side. Connections can be scoped and revoked through Relay and the provider.
Messages, publishing, purchases, deletion, commercial changes, and other sensitive work can wait with the exact consequence visible.
Relay records the actor, source, policy, time, provider result, and recovery path for executed work.
Stable request keys, retries, stop conditions, and provider-aware runners help prevent duplicate or out-of-policy action.
Relay does not publish certification, compliance, uptime, or model-training claims that have not been completed and documented.
Scoped authentication, organization permissions, server-side secrets, approval policy, and attributable activity.
Formal subprocessors, retention details, model-provider policy, trust materials, and any verified compliance roadmap.
Report a security issue without customer data or secrets to security@getonrelay.com.
Begin with one workflow, connect only the tools it needs, review the available read and write capabilities, and keep consequential actions behind approval.
Choose one job and its minimum required data.
Review provider scopes and organization permissions.
Test with approval before expanding autonomy.
Connect only the tools that job needs. Set the approval boundary. See the result before expanding.