Help: the vault¶✎ edit
Your vault keeps secrets (API keys, access tokens) for the AI agents you allow, so nobody pastes a secret into a chat. It's yours, the same on every project: Settings → AI permissions → Vault (/ai/vault).
Using it¶✎ edit
- The tab opens with Add on top and then one row per secret: its name, its note and the agents allowed to use it, as chips. Tap a row and its details open underneath it, in place — one at a time.
- Add a secret: a name (
github-pat), the value and a note. After you save it, the value is never shown again, to anyone: the row shows only its last four characters. - A value can be several lines, or a small JSON. A service that needs an endpoint, a region, a bucket and a key pair at once is one secret, not five; your agent reads the text back exactly as you pasted it and makes sense of it itself. The last four shown are of the whole text, so that is what you paste again when you allow another token.
- + allow a token: pick one of your AI tokens from the list (grouped by project) and give the value again. d2 checks it's the saved value (by its last four) and seals a copy for that token only. A token that has never been used shows Waiting for this agent to connect once: its lock key is made the first time it's used, so pick it after that.
- Your agent reads it with its own token:
GET /api/v2/vault/<name>(or the MCP toolvault_get). Any other token getsE_SECRET. - ✕ on an allowed chip takes it back at once. Revoking a token takes back all its secrets.
- Replace value: the tokens allowed now get the new value; you don't need to allow them again.
- Last reads lists every read and refusal (90 days); Notify me on each read sends you a notice per read. A refusal always sends one.
- Limits: 50 secrets, 8 KB each, 30 reads a minute per token.
How it's kept safe¶✎ edit
Nothing d2 stores can open a secret. Each AI token has a key pair whose private half is worked out from the token itself and never stored; d2 keeps only the public half. A secret is stored only as copies sealed to the public keys of the tokens you allowed, so the database, its backups and the server's settings can't open it. When your agent asks with its token, d2 works out that token's private key, opens its copy in memory, answers and forgets it. Secrets never appear in topics, history, drafts, search, exports, archives, logs, flows or your rules.
FAQ¶✎ edit
- I lost the value. Can I see it? No: nobody can, that's the point. Replace it with a new one.
- Why give the value again to allow a token? d2 has no copy it could open to seal for the new token.
- Can my project's rules use a secret? No. A rule that can read a secret could send it anywhere.