Orkestia
Blog
Product pages

Vault

Orkestia Vault keeps your organization's API keys, passwords and certificates encrypted, controls who can use them, records every access, and lets workflows and agents call an API with a secret they never see

TL;DR

  • One place for your organization's secrets. API keys, passwords, tokens and certificates live at paths such as stripe/prod/api-key, with versions you can go back to.
  • Encrypted with a key unique to your organization. Values are never stored or shown in plain text, except when someone allowed to reveals one.
  • Nobody gets a value by default. Owners and admins can do everything. Members and Staff agents need a policy, and a matching deny always wins.
  • Use a secret without seeing it. With API access, the Vault makes the API call for you, only to the hosts you allowed, and returns the response without the secret.
  • Everything is recorded. Every write, reveal, use and refusal appears in the audit log.

What is in the Vault

AreaWhat you do therePage
SecretsAdd a secret, write a new version, reveal it, delete or restore itSecrets
PoliciesDecide which members, roles and Staff agents may read, use or change which secretsAccess policies
API accessLet workflows and agents call an API with a secret they never receiveAPI access
Audit logSee who read, wrote, used or was refused whatAudit log and keys
Encryption keyRotate your organization's keyAudit log and keys

Open it in the Console at app.orkestia.dev/vault (Infrastructure → Vault). Everything you can do there, you can also do from the API, an SDK or an AI assistant, through the vault.* workflows listed in the reference.

Guides

Secrets

Paths, versions, safe updates, reveal, delete and restore.

Access policies

Who may do what, and examples you can copy.

API access

Call an API with a secret the caller never sees.

Audit log and keys

Read the audit trail and rotate your organization's key.

Reference

Every vault.* workflow, errors, limits and troubleshooting.

Ask your AI assistant

prompts
Store my Stripe test key in the Orkestia Vault at stripe/test/api-key.
List the vault secrets I can see under aws/.
Let my Staff agent call api.github.com with the secret at github/ci/token, without being able to read it.
Show me every refused vault access from the last 24 hours.

For AI agents

Do thisWith
Find secrets (no values)vault.secret.list, vault.secret.metadata.get
Call an API with a secretvault.http.request
Store a valuevault.secret.write: confirm with the user first
Reveal a valuevault.secret.read: shown once to the person who asked. Never repeat it in chat
Change policies, API access or keysvault.policy.*, vault.secret.usage.set, vault.key.rotate: confirm with the user first
Erase for goodvault.secret.destroy, vault.secret.metadata.delete: cannot be undone, always confirm

Prefer vault.http.request over vault.secret.read: the value then never reaches you or the conversation.