Settings architecture

Encrypted credentials and provider readiness for email, AI, and calls.

Settings is the provider boundary. The UI saves AWS SES, Twilio, and Gemini values; the backend encrypts secrets into SystemSettings and exposes masked reads plus connection tests.

Runtime flow

Feature services do not read provider secrets from the frontend. They resolve decrypted settings server-side when sending email, previewing Gemini voice, generating text, launching calls, classifying signals, or serving bot workflows.

Encrypted provider configuration
Rendering architecture diagram...

Implementation map

Frontend

/settings, MissingCredentials helper, api.settings.get/update/testSes/testTwilio/testGemini/previewGeminiVoice.

Backend

SettingsController, SettingsService, credential-encryption helpers, and gemini-text model resolver.

Data

SystemSettings singleton stores encrypted AWS, Twilio, and Gemini values plus verification status timestamps.

Providers

AWS SES sends email, Twilio places calls, Gemini handles text generation, signal classification, voice preview, and Live calls.