Your Low-Code Platform Is a Credential Store Whether You Planned It or Not.
I was on a call with a customer's IT lead four months after their system went live. He was calm, which was the strange part. Then he said the sentence I have not been able to unhear since: "We found our ERP key in a data export." It had been sitting in a table row the whole time. Someone in procurement had filled in a field labelled "Access Token" during go-live testing. That field was in the…
A low-code platform can accidentally become a credential store, even if it wasn't intended to be one. This was discovered by a customer's IT lead after their ERP system went live. The key to the ERP was found in a data export, sitting in a table row all along. The key had been entered during go-live testing by someone in procurement, who then unknowingly shared the export.
A low-code platform treats credentials as regular data, often storing them in fields alongside other data. These fields inherit permissions, export paths, audit trails, search indexes, and more from the surrounding data model. This means a password stored in a text field is treated as a record, not a password.
When a customer connects their ERP, the provider typically doesn't ask questions about who owns the key, where it lives, how long it lives, or who can read it. These questions usually come up during an incident. The key belongs to whoever entered it, which may be a former employee. The key lives in backups, clones, exports, screenshots, and more. It can live indefinitely if not properly managed.
The clone feature is particularly dangerous for credentials. Cloning an application also clones its connector configurations, potentially spreading the key to various environments and users. Exports, logs, screenshots, and even AI agents can inadvertently expose credentials. The platform's design makes it easy to accidentally expose credentials, even in well-intentioned situations like testing connections or generating error messages.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.