vault9 · Secrets Planned concept

Deliberate access to agent credentials.

We are exploring a dedicated credential service with scoped grants, revocation, and rotation. Delivery methods and security boundaries are still being designed; vault9 is not a replacement for the current run9 or drive9 secret features.

Scope is subject to change. No public release or API is announced.

Credential storageScoped grantsRotationRevocation
proposed workflow

Choose who may use a credential, and how.

The concept starts with an explicit credential owner, a recipient, and a permitted use. Different delivery methods expose credentials differently, so storage, access, rotation, and revocation need clear boundaries rather than one blanket secrecy guarantee.

credential ownership scoped access delivery controls
vault9 · concept
1. Identify the credential owner and intended use.

2. Grant access to a defined recipient and scope.

3. Review delivery, rotation, and revocation behavior.
areas we're exploring

Store. Grant. Deliver.

We are exploring credential management with explicit ownership and exposure rules.

01 · Store

Credential ownership

Explore centralized credential storage and rotation, with clear ownership, retention, and access controls.

02 · Grant

Scoped authorization

Explore grants for a specific recipient and purpose. Expiry and revocation semantics, including credentials already delivered, remain to be defined.

03 · Deliver

Defined security boundaries

Explore delivery methods for different workloads. Whether a process receives the secret value, and where it may persist, depends on the selected method.

share your requirements

What credential boundary do you need?

Tell us who should own a credential, who needs to use it, and how it should reach the workload.