Skip to content

How AuthHub keeps client access secure

Updated

Short answer: AuthHub stores client OAuth tokens in Infisical, a dedicated secrets manager. AuthHub's own database holds only a reference to each secret, never the token itself. Grants, automatic refreshes, sensitive token reads, disconnects and cleanup failures are written to an audit log. AuthHub is not SOC 2 certified.

This page explains what that means in practice: where tokens live, which platforms refresh on their own, what the audit log records (and what you can't see yet), and what actually happens when you revoke access.

Where client tokens are stored (Infisical)

When a client approves access through your AuthHub link, the platform returns OAuth tokens to AuthHub. We write them straight to Infisical, a secrets-management platform. The stored secret contains the access token, the refresh token (if the platform issues one), the expiry time and the granted scopes.

AuthHub's PostgreSQL database never holds the token. It holds:

  • the name of the Infisical secret (a reference, not the token)
  • connection status (active, expired, invalid, revoked)
  • expiry and last-refresh timestamps
  • the scopes and the assets the client selected

AuthHub's API authenticates to Infisical with its own machine identity, and only server-side code reads tokens back. Encryption of the stored secrets is handled by Infisical, not by AuthHub code. For how Infisical encrypts and protects secrets, see Infisical's security documentation.

The same pattern covers your agency's own platform connections and other credentials AuthHub stores for you, such as webhook signing secrets.

Token refresh and expiry

Access tokens expire. What happens next depends on the platform:

PlatformWhat AuthHub does
Google (Google Ads, GA4 and other Google connections)Refreshes automatically with the stored refresh token
LinkedInRefreshes automatically
SnapchatRefreshes automatically
Meta (Facebook, Instagram)Can't refresh silently. When the token expires, the connection is marked expired and the client needs to reconnect.
TikTokReconnect required when access expires
Manual / invite-based platforms (e.g. Pinterest, Shopify, Klaviyo, Mailchimp)No token to refresh. Access lives inside the platform.

Every 12 hours, a background job looks for connections that expire within the next seven days and queues a refresh for the platforms that support it. The new tokens go back into Infisical. If a refresh fails because the platform says the grant is no longer valid, the connection is flagged for reconnection rather than retried forever. Brief provider outages are retried.

Refresh can't fix everything. Clients can revoke access, change passwords, or lose admin rights on their side, and platforms can end a grant on their own schedule. AuthHub keeps access working where the platform allows it; it can't promise access never expires. For the platform-by-platform detail, read our guide to OAuth token management for agencies.

What the audit log records

AuthHub writes security-relevant events to an audit log stored in its own database. Each row records the action, the connection or request it touched, the platform, and, where available, the user's email, IP address and user agent, with a timestamp. Events include:

  • Grants: a client authorizes a platform and its connection is created
  • Asset selection: the client chooses which ad accounts, pages or properties to share
  • Token reads: when AuthHub reads a stored Meta or Google token for a sensitive operation, such as verifying access or removing it
  • Automatic refreshes: success, "reconnect required", or failure
  • Agency connections: your agency connecting or disconnecting its own platform accounts, and their refreshes
  • Requests: an access request being cancelled
  • Cleanup failures: when Meta access removal or token deletion from Infisical doesn't complete
  • AI agents: creating, updating or revoking a personal-agent (MCP) grant, and the operations an agent runs

What you can see today: there is no full audit-log screen in the AuthHub app yet. Each client has an Activity timeline showing requests created, client authorizations and connections established. Connected AI agents show when they were last used, and an agent with activity permission can list its own recent activity. AuthHub doesn't publish a fixed retention period for audit records.

Revoking access and offboarding a client

There are four places you can revoke, and they do different things:

1. Delete a client in AuthHub. AuthHub revokes every connection for that client before it deletes the record.

  • For every platform, it deletes the stored tokens from Infisical and marks the authorizations revoked. AuthHub can no longer act on that client's accounts.
  • For Meta, it goes further. Before deleting the token, AuthHub removes the Meta asset access it recorded granting (pages, ad accounts, catalogs and datasets shared with your business, users or system users), then revokes AuthHub's app permission on the client's Meta account.
  • For other platforms (Google, LinkedIn, TikTok, Snapchat and the rest), deleting AuthHub's tokens does not remove any user, partner or manager-account access that was granted inside the platform itself. Remove that in the platform's own settings, or ask the client to.
  • If Meta or Infisical doesn't confirm the cleanup, the connection is marked invalid, the failure is logged, and the delete stops so it can be retried. It won't report success when cleanup failed.

2. Disconnect your agency's own platform account from the Connections page. AuthHub deletes the stored tokens and logs the disconnect. For Meta, it also revokes AuthHub's app permission and any system-user tokens it created first.

3. Cancel a pending access request. The link stops working, and the cancellation is logged.

4. Revoke an AI agent. Under Settings → Agents, revoking a personal-agent grant cuts that agent off immediately, and the revocation is logged.

Your clients stay in control too. They can remove access at any time from the platform's own settings (Google account permissions, Meta Business settings and so on), without going through AuthHub.

Compliance: what we have and what we don't

AuthHub is not SOC 2 certified. We don't hold SOC 2, ISO 27001 or any other security certification, and we don't claim to be "SOC 2 ready." If your procurement process requires a SOC 2 report, AuthHub won't meet that requirement today.

What we have:

  • client and agency OAuth tokens stored in Infisical, with only secret references in our database
  • an audit log of grants, refreshes, sensitive token reads, disconnects and cleanup failures
  • revocation that deletes stored tokens and, for Meta, removes the platform-side access AuthHub granted

Platforms

AuthHub connects 15+ platforms, including Meta, Google Ads, GA4, LinkedIn, TikTok and Snapchat, plus invite-based platforms. If you're weighing tools, see how we compare with Leadsie, AgencyAccess and ClientInvite. If AI agents will use client access, read MCP OAuth for agencies.

Security FAQ

Where are client tokens stored?

In Infisical, a secrets-management platform. AuthHub's database stores only the name of each Infisical secret, along with connection status, expiry, scopes and selected assets. It never stores the token itself.

Is AuthHub SOC 2 certified?

No. AuthHub is not SOC 2 certified and holds no other security certification. Our security controls are Infisical token storage and an audit log of access events.

Can I see who accessed a client account?

AuthHub logs grants, refreshes, sensitive Meta and Google token reads, disconnects and cleanup failures, with the user's email and IP address where available. There's no full audit-log screen in the app yet; each client's Activity tab shows requests, authorizations and connections.

What happens when a token expires?

Google, LinkedIn and Snapchat connections refresh automatically before expiry. Meta and TikTok can't refresh silently, so the connection is marked expired and the client needs to reconnect. Clients and platforms can also end access early, so no tool can guarantee access never expires.

How do I revoke access?

Delete the client in AuthHub. That deletes its stored tokens from Infisical for every platform. For Meta, AuthHub also removes the asset access it granted and revokes its app permission. On other platforms, remove any access granted inside the platform from that platform's settings.

Does revoking in AuthHub remove access inside Google or LinkedIn?

No. It removes AuthHub's tokens, so AuthHub can no longer act. Users or partners added inside Google Ads, LinkedIn or other platforms stay until you or the client remove them there. Meta is the exception: AuthHub removes the Meta asset access it recorded granting.

Get started

Plans are priced by active clients: $29/month for 5, $79/month for 20, $149/month for 50. See pricing →