Vault (admin only)¶
Opened from the account menu (bottom-left) under Administration, or from ⌘K.
The encrypted credential store: every API key, bot token and service password. You can add, rename and delete entries, and set per-agent overrides so two agents using the same credential name authenticate as different identities.
Who can see a stored value. An admin can reveal one here in the dashboard.
An agent cannot, by default: asking the vault for a credential returns a
masked preview (PKBM************), enough to confirm which key is stored
without putting the secret in the conversation. The full value is an explicit,
owner-only request that needs human approval before it reaches the agent. So an
agent can list names and use a credential freely, and only a person can turn
one back into plaintext.
Rekey changes the vault passphrase and re-encrypts every stored secret under the new one. Use it if the passphrase may have been exposed.
The vault re-locks whenever the server or dashboard restarts, and the dashboard prompts you to unlock it before anything that needs a credential can run.