Confluence Authentication
Confluence publishing uses two credential layers: MULESOFT_CLIENT_ID and MULESOFT_CLIENT_SECRET identify the service to the gateway, while a per-user PAT authorizes Confluence. /knowledge confluence-connect captures the PAT in a private Slack modal.
The PAT is encrypted with the same TOKEN_ENCRYPTION_KEY boundary used for GitHub OAuth. Its filename is a digest of the Slack user ID; plaintext is never persisted. The token directory must be persistent if connections must survive restarts. Publishing retrieves the PAT for the draft creator and sends it to the configured MCP endpoint; logs and audit events omit it.
PAT issuance, expiry, rotation, and deletion processes are TO_BE_CONFIRMED. See Connect Confluence.