Definition
A secret vault is encrypted storage for the credentials an agent needs, injected at runtime so keys are never written into prompts, code, or configuration files.
In practice
The default alternative is what most setups start with: an .env file, a few keys pasted into a config, and a shell history full of tokens. It works immediately and it is the arrangement people regret, because rotating a key then means hunting through every place it was pasted, and any of those places can leak. A vault turns rotation into one edit and keeps the value out of logs and prompts. The scoping rule matters as much as the storage: one credential per integration, read-only where the job is read-only, so revoking one thing does not stop everything.
Example
A founder's agents started with an .env file on a laptop and the same API key pasted into three configs. When the key showed up in a screenshot, rotating it meant finding every copy. After moving to a secret vault, each integration has its own credential, the value never appears in prompts or logs, and the next rotation is a single edit rather than a search through every file.
Common questions about secret vault
Why use a secret vault instead of an .env file?
An .env file works until a key has to be rotated or leaks: then every copy has to be found by hand, and any of them may already sit in a log or a screenshot. A secret vault stores each credential once, encrypted, injects it at runtime, and turns rotation into one edit.
How should credentials in a secret vault be scoped?
Scope each credential in a secret vault to one integration and the least access the job needs, such as read-only where the agent only reads. Then revoking or rotating one key affects only one job, and a compromised credential can do little beyond the single task it was issued for.
Read more
Nearby terms
All 25 termsRun agents without the homework
Qoren runs OpenClaw, Hermes, and Codex agents in managed environments, with the restarts, secrets, schedules, and spend caps handled for you.