Configure AES encryption
SetLANGGRAPH_AES_KEY to encrypt checkpoint blobs automatically:
-
Add
pycryptodometo your dependencies inlanggraph.json: -
Set
LANGGRAPH_AES_KEYto a 16, 24, or 32-byte key for AES-128, AES-192, or AES-256, respectively.
Encrypt JSON fields
SetLANGGRAPH_AES_JSON_KEYS to a comma-separated list of JSON keys to encrypt:
langgraph_version, langgraph_api_version, langgraph_plan, langgraph_host, langgraph_api_url, langgraph_request_id, langgraph_auth_user_id, and langgraph_auth_permissions.
Rotate AES keys
AES key rotation requires Agent Server version
0.17.0.dev3 or later, the PostgreSQL checkpointer with PREFER_GRPC_CHECKPOINTER=true, and the Go store with LANGGRAPH_STORE_BACKEND=grpc. Python, custom, SQLite, and MongoDB checkpointers do not support rotation.LANGGRAPH_AES_KEY. Key envelopes identify which configured key decrypts each value. When Agent Server reads data encrypted with an old key, it returns the plaintext and lazily re-encrypts the stored value with the current key.
To rotate a key:
-
Configure the current primary key and future key on every replica:
- Roll out this configuration to every replica.
-
After every replica can decrypt both keys, switch
LANGGRAPH_AES_KEYto the future key. -
Retain the old key in both compatibility settings:
LANGGRAPH_AES_LEGACY_KEYdecrypts untagged historical ciphertext.LANGGRAPH_AES_FALLBACK_KEYSdecrypts tagged ciphertext created with an old key. - Keep old keys configured until telemetry confirms they are no longer needed.
Related
Connect these docs to your agent of choice via MCP for real-time answers.

