Settings architecture
Encrypted credentials and provider readiness for email, AI, and calls.
Settings is the provider boundary. The UI saves AWS SES, Twilio, and Gemini values; the backend encrypts secrets into SystemSettings and exposes masked reads plus connection tests.
Runtime flow
Feature services do not read provider secrets from the frontend. They resolve decrypted settings server-side when sending email, previewing Gemini voice, generating text, launching calls, classifying signals, or serving bot workflows.
Implementation map
Frontend
/settings, MissingCredentials helper, api.settings.get/update/testSes/testTwilio/testGemini/previewGeminiVoice.
Backend
SettingsController, SettingsService, credential-encryption helpers, and gemini-text model resolver.
Data
SystemSettings singleton stores encrypted AWS, Twilio, and Gemini values plus verification status timestamps.
Providers
AWS SES sends email, Twilio places calls, Gemini handles text generation, signal classification, voice preview, and Live calls.