Product pages
Vault
Orkestia Vault keeps your organization's API keys, passwords and certificates encrypted, controls who can use them, records every access, and lets workflows and agents call an API with a secret they never see
TL;DR
- One place for your organization's secrets. API keys, passwords, tokens and certificates live at paths such as
stripe/prod/api-key, with versions you can go back to. - Encrypted with a key unique to your organization. Values are never stored or shown in plain text, except when someone allowed to reveals one.
- Nobody gets a value by default. Owners and admins can do everything. Members and Staff agents need a policy, and a matching
denyalways wins. - Use a secret without seeing it. With API access, the Vault makes the API call for you, only to the hosts you allowed, and returns the response without the secret.
- Everything is recorded. Every write, reveal, use and refusal appears in the audit log.
What is in the Vault
| Area | What you do there | Page |
|---|---|---|
| Secrets | Add a secret, write a new version, reveal it, delete or restore it | Secrets |
| Policies | Decide which members, roles and Staff agents may read, use or change which secrets | Access policies |
| API access | Let workflows and agents call an API with a secret they never receive | API access |
| Audit log | See who read, wrote, used or was refused what | Audit log and keys |
| Encryption key | Rotate your organization's key | Audit log and keys |
Open it in the Console at app.orkestia.dev/vault (Infrastructure → Vault). Everything you can do there, you can also do from the API, an SDK or an AI assistant, through the vault.* workflows listed in the reference.
Guides
Ask your AI assistant
prompts
Store my Stripe test key in the Orkestia Vault at stripe/test/api-key.
List the vault secrets I can see under aws/.
Let my Staff agent call api.github.com with the secret at github/ci/token, without being able to read it.
Show me every refused vault access from the last 24 hours.
For AI agents
| Do this | With |
|---|---|
| Find secrets (no values) | vault.secret.list, vault.secret.metadata.get |
| Call an API with a secret | vault.http.request |
| Store a value | vault.secret.write: confirm with the user first |
| Reveal a value | vault.secret.read: shown once to the person who asked. Never repeat it in chat |
| Change policies, API access or keys | vault.policy.*, vault.secret.usage.set, vault.key.rotate: confirm with the user first |
| Erase for good | vault.secret.destroy, vault.secret.metadata.delete: cannot be undone, always confirm |
Prefer vault.http.request over vault.secret.read: the value then never reaches you or the conversation.
