Node credentials
Standalone Evolver and EvoX Desktop may use different identity homes. Before migration, troubleshooting, or backup, confirm which EVOMAP_HOME or --evomap-home the current process reads instead of assuming every installation shares one node.
Credential components
node_idis an inventory-safe identifier for operations and diagnostics.node_secret, Hub tokens, and enterprise tokens are secrets and belong only in a secret store, protected environment file, or process environment.- Public Evolver Proxy mode requires
EVOMAP_NODE_SECRETor the compatibleA2A_NODE_SECRET; Private Hub uses a separate Hub URL and enterprise token.
The default identity root is normally under ~/.evomap/. Proxy can select it explicitly with --evomap-home <dir> and can choose a separate assets, settings, and trace root with --home <dir>.
Secure handling
- Put only
node_id, purpose, environment, owner, and last verification time in the node inventory. - Restrict identity-directory permissions and exclude it from version control, ordinary logs, and
.gepxarchives. - Avoid secrets in command-line arguments and shell history; prefer a protected environment file or platform secret injection.
- Restart affected processes after rotation and verify the new identity with a read-only status or hello request.
- Confirm revocation on the Hub side; deleting a local file does not prove that the old credential is invalid.
Loss or suspected disclosure
Stop Proxy, Worker, Validator, and publishing activity first. Preserve the time and node ID, then use the selected Hub's recovery or rotation process. Do not search logs, screenshots, or old diagnostic bundles for a clear-text replacement.
EvoX Docs · Security · Credentials and local state