Vault
Secrets live in the vault encrypted, keyed by a name you choose - logins or standalone values. Spaces mount vault prefixes, so a runtime uses a secret by reference and your code never touches the plaintext.
Store a secret
A login secret holds a username, password, and optional TOTP:
A value secret holds a single string:
Read secrets
get returns metadata only; value returns the decrypted secret.
TOTP
Generate the current one-time code for a login secret that has a TOTP seed:
Update and delete
Mount into a space
Allow prefixes on the space environment to give its runtimes access:
Next
- Spaces - mount vault prefixes
- AI Providers - model keys, stored separately
- Account & Org - per-customer isolation

