Integrations at a glance
How Juno handles credentials
These practices apply to every integration in this toolkit:- Least privilege β Juno requests only the scopes each feature needs. Optional features (for example, recording download) use separate, optional scopes.
- Encryption at rest β OAuth tokens and API credentials are encrypted before storage and are never exposed to the browser or client apps.
- No passwords stored β Juno never sees or stores your usersβ passwords for any integrated service.
- Revocable at any time β every integration can be disconnected from Juno or revoked from the providerβs admin console. Each page includes revocation steps.
- Tenant isolation β credentials and synced data are scoped to your organization and are never shared across Juno customers.
Each integration page lists the exact permission strings so you can match them against the consent screen your admins will see.

