No passwords for connected services
Gmail is connected with Google OAuth. Ahim does not request or store a Google password.
Ahim must earn the right to operate. Connections are limited, visible and removable from the user’s account.
Gmail is connected with Google OAuth. Ahim does not request or store a Google password.
The current Gmail refresh token is encrypted on the server. It is never exposed through the browser interface.
The Gmail disconnect endpoint asks Google to revoke the token and always deletes Ahim’s local token. This is implemented now for Gmail, the only external connector currently stored by the prototype.
Bank passwords, card CVV codes, recovery phrases, private keys and exchange withdrawal secrets are prohibited. Future finance integrations must use official consent-based providers.
The current prototype is local, not a production banking or identity service. Each new connector needs its own security review before launch.
See the product