Google Jules data and execution use the server-side JULES_API_KEY; no provider credential is sent to the browser.
Local drafts are saved to IndexedDB and restored after reload.
No browser API key is requested or persisted; local drafts remain fully usable without one.
GitHub workspace choices are loaded server-side and limited to platphorm-* repositories. Unconfigured execution is reported as unsupported, never as a created handoff.