Installation
Install agents-vault from crates.io. The installed command is av.
Prerequisites
You need Rust 1.88 or newer, including Cargo. Follow Rust’s installation guide to install or update it.
Cargo builds the CLI from source, including SQLCipher and OpenSSL. Install your platform’s build tools first:
| Platform | Required tools |
|---|---|
| Linux | A C compiler, linker, make, and Perl. Use your distribution’s development toolchain packages. |
| macOS | Xcode Command Line Tools: xcode-select --install. |
| Windows | Visual Studio Build Tools with Desktop development with C++ and the Windows SDK; Perl and NASM for OpenSSL. Use the MSVC Rust toolchain. |
Install
cargo install agents-vault --lockedav --version--locked uses the dependency versions included with the release. This installs the executable; it does not create or unlock a vault.
Next: follow the quickstart to run a project.
Make av available in your shell
If your shell cannot find av, open a new terminal first. Rustup normally adds Cargo’s executable directory to PATH.
If it is still missing, add the relevant directory:
| Platform | Default directory |
|---|---|
| Linux and macOS | ~/.cargo/bin |
| Windows | %USERPROFILE%\.cargo\bin |
A custom CARGO_HOME changes that location to its bin subdirectory.
Update or uninstall
Install the latest release:
cargo install agents-vault --locked --forceAdd --version 0.1.0 to install a specific release.
Remove the executable:
cargo uninstall agents-vaultYour project files, vault, and recovery material remain after uninstalling.
Protected services and MCP
The CLI supports project variables and local direct secret delivery. A protected service needs a separate installation:
The service uses a separate vault. Proxy credentials remain synthetic while the custody checks are incomplete.
To approve actions through a compatible client, install the separate MCP Apps adapter.
Build from source
For development, clone the repository, then run from its root:
cargo build --locked -p agents-vault --bin av./target/debug/av --helpOn Windows, the executable is target\debug\av.exe.
Source builds of the broker and MCP adapter also need their web assets. See console and MCP build instructions.