DefangStation

Security & credentials

What Defang stores, what stays on your Station, what answers at its public address, and the boundaries that keep one account’s work away from another’s.

What is kept where

Defang’s systems

Who you are, your sign-in sessions, your Station’s settings and current status, the progress of launches, stops and destroys, and a log of those events.

Your Station

Repository files, terminal sessions, agent configuration, and the logins Claude Code and Codex save there.

Every Station belongs to one account

That is checked on every request, against who is signed in rather than against anything in the address or the page. There is no identifier you or anyone else can pass to reach another account’s Station.

What answers at your Station’s address

Your Station has its own address on the internet, so your agents can be reached from outside as well as reach out. Three kinds of traffic arrive there, and each is handled differently on purpose.

Everything a person opens

The terminal, your sessions, the settings page and the page for moving files on and off your Station all sit behind a login, and repeated failed logins from the same place are blocked. Your Station’s web address is not a secret, so assume anyone can find it and count on the login to protect you. A certificate is issued for the address the moment your Station is built, and certificates are published in a public log that anyone can read.

Webhooks, the deliberate exception

A sender like GitHub cannot sign in, so the webhook path is served without a login. A signature on each request protects it instead. To add a source, tell an agent on your Station what to connect, for example: “Watch new issues on acme/website and open a draft pull request for each one.” It creates a secret for that one source and registers the webhook with the sender, or walks you through adding it yourself, and every signature is checked against that shared secret. Until you set a source up, the path does not exist and deliveries get a not-found error. If a sender reports one, run the setup instead of hunting for a different address. Once it is set up, anything unsigned is rejected. Whatever reaches your agent is marked as coming from outside, which tells the agent to treat it as content to examine, not instructions to follow.

Anything you choose to publish

If you have your agent serve a site from your Station, that site is public. It gets its own hostname and, on purpose, none of your Station’s sign-in, so do not put a staging database or an internal tool behind one. A site is published only when you ask for one. A running process never gets that by default.

Signing in

You sign in with Google, so there is no Station password to lose and we never see your Google one. If you think someone else has been in your account, write to support@defang.io and we will cut its sessions.

Launching, stopping and destroying

  • Each of those runs once, even if a button is pressed twice or a request is retried. The newest instruction always wins: an operation that finishes late cannot undo one that came after it.
  • Every change you can see is written to your mission log.
  • Destroying a Station means typing its name exactly.

Deleting an account

Destroy your Station first, then confirm by typing your email. You cannot delete your account while a Station is still running, so nothing is left behind with nobody to own it. Deleting your account then removes your Station and everything we hold about it.

Claude Code or Codex saves your login on your Station, the same way it would on your laptop. Defang never receives it.

The exception is a value you type into your Station’s environment settings yourself, such as an API key. That travels through us on its way there. It is not logged and not kept, but it does pass through, so you should know which of the two you are doing.