> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# Inventory encryption

> How Itential Gateway uses Fernet and HashiCorp Vault encryption for inventory passwords.

Itential Gateway supports local **Fernet** encryption and **HashiCorp Vault** for inventory passwords.

## Local encryption

**Fernet** encryption uses a 128-bit key to protect a password from being manipulated or read.

To enable local encryption, set the `fernet_key` value in the `properties.yml` file. You can use various methods to generate a **Fernet** key as outlined in the [section](#generating-a-fernet-key) below. Once enabled, passwords are encrypted by updating a current device or creating a new device. Existing passwords are not automatically encrypted.

The device types that support local encryption are **GRPC**, **Netmiko**, and **NetConf**.

> **Note**
>
> HTTP inventory encryption is currently not included.

### Example Fernet key

```yaml
fernet_key: "F-YE4se483yUZ56S88J3g10dPhKjio8r35sT5xJ4NSc="
```

### Generating a Fernet key

Various methods can be used to generate a Fernet key. You will need to generate your own Fernet key and keep it safe. If you lose your key, you will not be able to decrypt any passwords that have been encrypted. If someone gets access to the key, they will be able to decrypt those passwords.

Additional information on **Fernet** encryption is available on the [cryptography.io](https://cryptography.io/en/latest/fernet/) site.

## HashiCorp Vault encryption

Passwords are overwritten when a **HashiCorp Vault** integration is present and the device has a `vault_path` variable set with a string value of `"vault_path:vault_key"` in the device variables.

### Example device POST

```json
{
  "name": "iosxr-cloud",
  "variables": {
    "host": "sandbox-iosxr-1.cisco.com",
    "password": "",
    "username": "admin",
    "insecure": true,
    "vault_path": "network:password",
    "port": 57777
  }
}
```

If the `vault_path` variable is defined, it will overwrite the current password field.

> **Note**
>
> Full Vault integration must be set up first. See the [HashiCorp Vault](./hashicorp-vault-integration) integration guide.