Skip to content

Vault (admin only)

Opened from the account menu (bottom-left) under Administration, or from ⌘K.

The encrypted credential store: every API key, bot token and service password. You can add, rename and delete entries, and set per-agent overrides so two agents using the same credential name authenticate as different identities.

Who can see a stored value. An admin can reveal one here in the dashboard. An agent cannot, by default: asking the vault for a credential returns a masked preview (PKBM************), enough to confirm which key is stored without putting the secret in the conversation. The full value is an explicit, owner-only request that needs human approval before it reaches the agent. So an agent can list names and use a credential freely, and only a person can turn one back into plaintext.

Rekey changes the vault passphrase and re-encrypts every stored secret under the new one. Use it if the passphrase may have been exposed.

The vault re-locks whenever the server or dashboard restarts, and the dashboard prompts you to unlock it before anything that needs a credential can run.