WP Manifestindependent plugin directory
manifest / security / encrypt-ai-connector-keys

Encrypt AI Connector Keys self-updates

Repository for WordPress-Plugin Encrypt AI Connector Keys

by Thomas Zwirner · github.com/threadi/encrypt-ai-connector-keys

4stars
0forks

Install

No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:

wp plugin install https://github.com/threadi/encrypt-ai-connector-keys/archive/refs/heads/master.zip

Ships its own WordPress updater (built-in updater), so new versions show up under Dashboard → Updates.

With WordPress 7.0, the AI Client was integrated into the CMS. This allows users to store their API keys for accessing AIs in a central location within the backend. However, these keys are stored unencrypted in the database, which for some projects is a deal-breaker for using API keys in the AI Client.

This repository contains a small plugin that handles the encryption and decryption of these API keys. It uses the Crypt for WordPress, which has already proven its worth and supports various encryption methods. The key to decrypt the strings is not stored in the database but in separate files (wp-config.php, a generic MU plugin, or a custom file). This allows the API keys to be stored securely in the database by the AI Client.

Features

  • Encrypt any existing key on activation.
  • Encrypts any new API AI key entered under Settings > Connectors.
  • Decrypt encrypted API AI keys only when their use is requested.
  • Decrypt any existing key on deactivation.
  • No further settings necessary.

Usage

  1. Download the actual release ZIP (not the source ZIP) from GitHub.
  2. Install it in your WordPress and activate it.
  3. Enjoy the peace of mind that comes with knowing your data is secure.

Settings

There are no settings for this plugin. However, you can use this hook to control how encryption works:

add_filter( 'encrypt_ai_connector_keys_crypt_config', function( $config ) { // change the configuration here. return $config; });

The possible configurations are described here: https://github.com/threadi/crypt-for-wordpress?tab=readme-ov-file#parameters

Alternatives

The WordPress AI Client also includes an option to store API keys more securely. This can be done by using environment variables in the hosting environment. The key is stored in a hosting setting and then read by WordPress. The downside is that not all hosting providers support this, and it can be difficult for regular users to implement.