--- kind: task slug: tenant-scoped-cursor-connections title: Store per-tenant Cursor tokens and default sync mode plan_slug: multitenant-cursor-sync epic_slug: multitenancy status: ready priority: P1 tenant_id: global owner: unassigned cursor_todo_id: null updated_at: "2026-04-26" --- # Task summary Add tenant-level settings: **encrypted** Cursor token (or OAuth refresh), default `markdown_authoritative` vs `app_authoritative` mode from `config/CursorSync.md`. ## Description Never commit secrets to markdown. Admin UI or env-injected secrets for dev only. ## Subtasks - [ ] Settings table or reuse workspace settings JSON - [ ] Rotation path documented - [ ] E2E test with two fake tenants ## Owner or assignee Unassigned ## Status ready ## Estimation L ## Acceptance criteria - [ ] Token at rest encrypted or stored in vault integration stub. - [ ] Sync job loads credentials only for the tenant id on the job payload. ## Links to related Epic / Plan - Epic: `./Epic-multitenancy.md` - Plan: `../Plan-multitenant-cursor-sync.md`