Readable projects.Deliberate access.

Manage project values and encrypted credentials on your machine. Give a trusted command the values it needs, or explore reviewed proxy actions with synthetic credentials.

Agents VaultCredential reference
Reference
secret://example/tokenRefers to an encrypted credential
Access policy
Allowed: project (example)Use: approved commands only
No grants by default
New credentials have no release grants. Approve matching runs from an operator terminal.
av.tomlProject configuration
schema = 2 [project]id = "example" [values.SERVICE_TOKEN]type = "string"secret = "secret://example/token" [values.APP_ENV]type = "string"value = "development"
Illustrative project configuration

Configuration stays readable.Release stays explicit.

Direct delivery exposes real values.
Protected proxy custody remains under development.

How it works

Your command. A deliberate path.

For a reviewed proxy action, the command keeps its HTTPS destination. A temporary capability connects it to the broker, which checks the approved destination and inserts the synthetic credential upstream.

The flow is an illustrative synthetic action: command → Agents Vault → HTTPS provider. It is not a live approval. Host commands are not confined, and a provider may reflect an injected credential.

Understand proxy delivery

Your command

Keeps its HTTPS URL.

Temporary proxy capability

Agents Vault

Reviews the action.
Injects the credential upstream.

Command · host · version · limits

HTTPS provider

Receives the injected header.

Exact approved host
Illustrative synthetic action · Host commands are not confined.

Check the shape. Keep the secret.

Declare public values and credential references in av.toml. Select environment overrides, validate the configuration, and generate placeholder dotenv files without resolving credentials into them. The local example changes only the public APP_ENV value; the credential remains a placeholder.

Explore project configuration

.env.example
Example environment
APP_ENV="development"
SERVICE_TOKEN="<AV_SECRET:example/token>"

Illustrative development output. No credential is resolved.

Review the action. Then run.

New credentials have no release grants. For direct secrets, choose the executable and arguments, review the policy, and approve matching runs from an operator terminal. The local console manages credentials, one active action recipe, permissions, and decisions. The waiting CLI can resume after approval. A compatible MCP Apps harness can adopt its live request and present the frozen command, destination, credential version, runtime, and quotas.

Read about actions and approvals

  • CommandExecutable and arguments
  • DestinationExact host
  • CredentialSelected version
  • LimitsRuntime and request quotas

Know the current boundary.

SQLCipher is the initial storage adapter. Native keyrings are planned. Proxy actions currently use synthetic credentials; the host command is not confined. Linux and macOS component tests exist, while installed-platform and whole-agent custody gates remain open.

Build the CLI · See demonstrated behavior

Credential boundary: direct delivery exposes real values to its recipient. Protected proxy custody and installed macOS acceptance remain under development.

Read it your way.

Browse the guides, copy a page, or use the same documentation as plain text. Human guides and agent exports come from the same maintained Markdown.

Human guides · Agent index · Complete Markdown