Secrets
A secret is a value stored at a path, such as aws/prod/deploy or stripe/test/api-key. Each change adds a version, and the Vault keeps the latest ones (10 by default) so you can go back.
Paths
- Separate parts with
/:team/service/name. - Use letters, digits and
_ . @ = + -. - Plan paths around who needs access. Policies grant access by path, so
payments/**is easy to grant.
Add a secret
In the Console: Vault → Secrets → + Add secret. Enter a path, the value and an optional description.
From the API or an assistant, start vault.secret.write:
| Input | Meaning |
|---|---|
path | Where to store it |
value | The secret, up to 64 KiB |
cas | Optional safe update. 0 = create only. N = write only if the current version is N |
description | What the secret is for |
custom_metadata | Labels. These are not secret: never put secret material here |
max_versions | Versions to keep, 1 to 100 (default 10) |
cas. If someone else changed the secret in the meantime, the write fails with VAULT_CONFLICT instead of overwriting their change.Write a new version
In the Console, open the secret's Manage menu and choose New version. From the API, call vault.secret.write again on the same path. Earlier versions stay available.
Reveal a value
vault.secret.read shows the value once, to the person who asked. In the Console it appears in a dialog you can copy from, and is gone when you close it. Pass version to reveal an earlier one.
Every reveal is recorded in the audit log.
Use a secret in a workflow
vault.secret.resolve passes a secret to a step inside one of your workflows without showing it to anyone. It needs the resolve permission and cannot be started directly from the API.
List and inspect
vault.secret.listshows the paths you are allowed to see, never values. Filter withprefix.vault.secret.metadata.getshows one secret's versions, labels, API access settings, and who created and last changed it.
Delete, restore, destroy
| Workflow | What it does | Undo |
|---|---|---|
vault.secret.delete | Hides versions. They cannot be read or used | vault.secret.undelete |
vault.secret.undelete | Restores deleted versions | — |
vault.secret.destroy | Erases versions for good | None |
vault.secret.metadata.delete | Removes the secret and every version | None |
These act on the current version unless you pass versions.
In the Console, Delete removes the secret and all its versions. Anything that uses it stops working.
Vault
Orkestia Vault keeps your organization's API keys, passwords and certificates encrypted, controls who can use them, records every access, and lets workflows and agents call an API with a secret they never see
Access policies
Decide who may read, use, change or manage which secrets. Owners and admins can do everything; everyone else needs a policy, and deny always wins
