Keep your .env files out of the repo, encrypted and audited.
Each project has its own AES-256-GCM key, which the vault encrypts with a key-encryption key kept outside the database. Revealing, exporting or downloading a value needs a second factor from the last 10 minutes and writes a row to the audit log. Coding agents connect over MCP, the protocol they use to call tools, with tokens scoped to the projects you choose. Every token expires, and you can revoke it.
Have an invite link? Open it to create your account.
claude mcp add --transport http secret-store https://secretstore.sh/api/mcpClaude Code opens your browser, where you choose the scopes, the projects and a lifetime of 1, 30 or 90 days. Cursor takes the same URL in .cursor/mcp.json.
Threat model
- A database snapshot
- The snapshot holds AES-256-GCM ciphertext and project keys encrypted with a key that is not in the database. Nothing in it decrypts.
- A session cookie
- Anything sensitive still needs a second factor from the last 10 minutes. Revoke the session on the sessions page and it stops working within two minutes.
- An agent token
- It reaches only the projects and environment kinds you chose, and it expires. You can revoke it, and the audit log shows every use with the keys it read.
- A server auth secret
- Someone holding the server's token secrets can forge sessions and tokens, but cannot decrypt a value. Rotating them ends every session and token at once.
Secret Store does not protect against a fully compromised hosting account, which holds the key-encryption key, or a collaborator reading the values you gave them access to.