A vault for your secrets, with per-agent grants
Secrets now live in Settings, and you pick which agent can use which one, and where.
- There's a new Settings > Vault page. It shows each secret as metadata only (name, a short fingerprint, status, version, limits, and last use), and you can add, rotate, limit, or revoke entries there.
- You can grant one vault entry to one agent and narrow it to certain tools or hosts. If you withdraw a grant, it stops working on the agent's next use.
- A secret saved on an agent's record now actually reaches that agent's runs. Before, it couldn't.
- Agents can make an HTTPS call using a secret without ever seeing the value, and they get a masked response back. This is opt-in.
- There's a new automation setting for a secret's first use. Under Gated, an agent's first use of an entry pauses for your review.