Vault : Credentials that are used, never shown.
The credentials the organisation keeps: saved once, used without being seen, given for a time. The Vault hands a secret out as work done - a session opened, a request signed - and never as text on a screen.
What it does
Vault, point by point.
Saved once, write-only
A secret goes straight from the browser to the keeper, or the keeper makes it. After that there is no screen, and no door in the keeper, that returns it.
Safes with four levels
In a safe a person sees, uses, manages or owns. Seeing that a credential exists is not being able to use it.
Access with an end
A grant has a last day. People ask for access; whoever answers for the safe approves it from their cartable.
Sessions inside the platform
RDP and SSH open in the browser, already signed in. The person never learns the password. A session can be watched live, ended, and replayed afterwards.
A browser that is already signed in
Web systems open in a contained browser that the Vault signed in. An agent may drive it for the organisation - on a portal, on a supplier's site - without holding the login.
Bound to where it belongs
A credential is tied to the system it is for. Used in a web request, it goes only there, and its value is scrubbed from what comes back.
Rotation
Passwords and keys of servers are changed by the Vault itself, so the value in use is one nobody ever saw.
A record of every use
Who used what, when, for what - and one switch that stops every use at once.
See it work
Try to see the password
Two buttons. One of them is the whole idea of the Vault.
Servers safe
Demo•••••••••••••••• A credential in the Vault can be used. It cannot be read - by anyone.
- Rotated by the Vault, 2 days ago
- Saved by Omid, write-only, 3 weeks ago
Getting started
Three steps in.
- Open Vault and make a safe for your team.
- Add an item: type the secret once, or let the Vault make one.
- Give people use of it, with an end date.
Questions
What people ask about Vault.
Can an administrator read a password?
No. Nobody reads a value back - not the person who saved it, and not an administrator. It can be used, replaced, or rotated.
Where are the values kept?
In a dedicated secret store on a network of its own, behind a keeper that only acts on one-use tickets the platform signs.
How do agents use credentials?
Like people: by grant, for a time, for a purpose - and without ever reading the value.