Powder

Runtime settings

Change non-sensitive operational controls without rotating a secret or redeploying the Worker. Saved values apply to this environment and override its deployment defaults.

What stays in deployment configuration?

Credentials

API keys, OAuth signing material, database URLs, Twilio tokens, service-account JSON, webhook secrets, and connector authentication values.

Trust boundaries

Allowed origins, managed mailbox identities, Access audiences, public service origins, relay signing, and environment identity.

Infrastructure and rollout

Queues, Durable Objects, storage bindings, Gmail project/topic wiring, relay topology, file-config authority, and the conversation-summary cutover gate.