# Agents Vault

Readable projects. Deliberate access.

Manage project values and encrypted credentials on your machine. Give a trusted command the values it needs, or explore reviewed proxy actions with synthetic credentials.

**Credential boundary:** direct delivery exposes real values to its recipient. Protected proxy custody and installed macOS acceptance remain under development.

[Start with the CLI](https://av.syntropika.ai/docs/quickstart.md) · [Read the docs](https://av.syntropika.ai/docs/index.md) · [Understand the limits](https://av.syntropika.ai/docs/limits-and-trust.md)

## Configuration stays readable. Release stays explicit.

Direct delivery exposes real values. Protected proxy custody remains under development.

## Your command. A deliberate path.

For a reviewed proxy action, the command keeps its HTTPS destination. A temporary capability connects it to the broker, which checks the approved destination and inserts the synthetic credential upstream.

The flow is an illustrative synthetic action: command → Agents Vault → HTTPS provider. It is not a live approval. Host commands are not confined, and a provider may reflect an injected credential.

[Understand proxy delivery](https://av.syntropika.ai/docs/configuration-and-delivery.md)

## Check the shape. Keep the secret.

Declare public values and credential references in `av.toml`. Select environment overrides, validate the configuration, and generate placeholder dotenv files without resolving credentials into them. The local example changes only the public `APP_ENV` value; the credential remains a placeholder.

[Explore project configuration](https://av.syntropika.ai/docs/configuration-and-delivery.md)

## Review the action. Then run.

New credentials have no release grants. For direct secrets, choose the executable and arguments, review the policy, and approve matching runs from an operator terminal. The local console manages credentials, one active action recipe, permissions, and decisions. The waiting CLI can resume after approval. A compatible MCP Apps harness can adopt its live request and present the frozen command, destination, credential version, runtime, and quotas.

[Read about actions and approvals](https://av.syntropika.ai/docs/actions-and-approvals.md)

## Know the current boundary.

SQLCipher is the initial storage adapter. Native keyrings are planned. Proxy actions currently use synthetic credentials; the host command is not confined. Linux and macOS component tests exist, while installed-platform and whole-agent custody gates remain open.

[Build the CLI](https://av.syntropika.ai/docs/quickstart.md) · [See demonstrated behavior](https://github.com/syntropika/agents-vault/blob/main/docs/implementation-status.md)

## Read it your way.

Browse the guides, copy a page, or use the same documentation as plain text. Human guides and agent exports come from the same maintained Markdown.

[Human guides](https://av.syntropika.ai/docs/index.md) · [Agent index](https://av.syntropika.ai/llms.txt) · [Complete Markdown](https://av.syntropika.ai/llms-full.txt)
