Readable projects.Deliberate access.
Manage project values and encrypted credentials on your machine. Give a trusted command the values it needs, or explore reviewed proxy actions with synthetic credentials.
- Reference
secret://example/tokenRefers to an encrypted credential- Access policy
- Allowed: project (example)Use: approved commands only
- No grants by default
- New credentials have no release grants. Approve matching runs from an operator terminal.
schema = 2 [project]id = "example" [values.SERVICE_TOKEN]type = "string"secret = "secret://example/token" [values.APP_ENV]type = "string"value = "development"Configuration stays readable.Release stays explicit.
Direct delivery exposes real values.
Protected proxy custody remains under development.
Your command. A deliberate path.
For a reviewed proxy action, the command keeps its HTTPS destination. A temporary capability connects it to the broker, which checks the approved destination and inserts the synthetic credential upstream.
The flow is an illustrative synthetic action: command → Agents Vault → HTTPS provider. It is not a live approval. Host commands are not confined, and a provider may reflect an injected credential.
Your command
Keeps its HTTPS URL.
Temporary proxy capabilityAgents Vault
Reviews the action.
Injects the credential upstream.
Command · host · version · limitsHTTPS provider
Receives the injected header.
Exact approved hostCheck the shape. Keep the secret.
Declare public values and credential references in av.toml. Select environment overrides, validate the configuration, and generate placeholder dotenv files without resolving credentials into them. The local example changes only the public APP_ENV value; the credential remains a placeholder.
APP_ENV="development"
SERVICE_TOKEN="<AV_SECRET:example/token>"Illustrative development output. No credential is resolved.
Review the action. Then run.
New credentials have no release grants. For direct secrets, choose the executable and arguments, review the policy, and approve matching runs from an operator terminal. The local console manages credentials, one active action recipe, permissions, and decisions. The waiting CLI can resume after approval. A compatible MCP Apps harness can adopt its live request and present the frozen command, destination, credential version, runtime, and quotas.
- CommandExecutable and arguments
- DestinationExact host
- CredentialSelected version
- LimitsRuntime and request quotas
Know the current boundary.
SQLCipher is the initial storage adapter. Native keyrings are planned. Proxy actions currently use synthetic credentials; the host command is not confined. Linux and macOS component tests exist, while installed-platform and whole-agent custody gates remain open.
Credential boundary: direct delivery exposes real values to its recipient. Protected proxy custody and installed macOS acceptance remain under development.
Read it your way.
Browse the guides, copy a page, or use the same documentation as plain text. Human guides and agent exports come from the same maintained Markdown.