# Vault · Encrypted credential storage

## No more  .env files.

Encrypted credential storage for AI agents. Store API keys, OAuth tokens, and login credentials with scoped access, automatic rotation, and audit trails.

[AES-256-GCM](https://console.loomal.ai/)  
Encryption  
Per-identity  
Scoped access  
Auto  
OAuth refresh  
One-click migration

## Drop your .env. Walk away.

Drag a .env file into the console. Loomal auto-detects secret types — API keys, database URLs, OAuth tokens — categorizes them, and stores each one encrypted with AES-256-GCM. Delete the .env from your repo forever.

### .env detected · 4 secrets  
`STRIPE_KEY`  
`API_KEY`  
`DATABASE_URL`  
`CUSTOM`  
`GITHUB_TOKEN`  
`OAUTH`  
`ADMIN_PASSWORD`  
`LOGIN`  
stored · encrypted · scoped

## Encrypted at every layer.

Per-credential data encryption keys, each wrapped by org-level KMS keys. Even if the database is fully compromised, encrypted values are useless without the KMS key hierarchy. Not security theater.

### Envelope encryption  
Org KMS key  
Wraps · DEK per credential  
AES-256-GCM ciphertext

## Revoke once. Cascades everywhere.

Every credential access traces through Human → Org → Identity → Credential. Pull one node and everything downstream stops instantly. No orphaned secrets. No cleanup scripts. No grep'ing through .env files.

## The capabilities

### Built for autonomous credential management.

- Scoped access per identity: Every credential is bound to a specific agent identity. Sub-agents receive attenuated access. Every read, write, and delete is audit-logged.
- OAuth auto-refresh: Store access and refresh tokens together. Loomal refreshes access tokens before they expire. Your agent never sees a 401.
- Zero-downtime rotation: Overwrite a credential and the next API read returns the new value instantly. No config files, no deployments, no downtime.
- Delegation chain: Every access traces through Human > Org > Identity > Credential. Revoke an identity and every credential it owns becomes instantly inaccessible.
- Typed credentials: Store credentials with semantic types — API_KEY, OAUTH, LOGIN, CUSTOM. Each has structured fields so your agent knows what it's working with.
- Native MCP integration: Access vault credentials directly from Claude Desktop, Cursor, or any MCP client via vault.store / get / list / delete tools.

## In production

### Where Vault saves the most time.

- **Third-party API access:** Stores and retrieves API keys for Stripe, Twilio, HubSpot, or any third-party service. Encrypted at rest, scoped per identity.
- **Autonomous service login:** Stores usernames, passwords, and TOTP seeds. Agents complete full login flows including 2FA — no human paste-in.
- **Database connection strings:** Store DB URLs, connection strings, and certificates securely. Agents retrieve at runtime — no hardcoded creds, no .env in git.
- **Payment processing:** Retrieves Stripe or payment processor API keys to create charges, generate invoices, or send payment links. Audit-logged.
- **OAuth workflow automation:** Stores OAuth tokens for Google Workspace, Microsoft 365, HubSpot. Tokens auto-refresh so the agent maintains persistent access.
- **Multi-agent credential sharing:** Parent agents delegate attenuated access to sub-agents. Lead-gen agent shares read-only CRM access without exposing the full token.

## Stop hardcoding secrets.

Migrate from .env files in one click. Store, rotate, and audit every credential your agents use.

## We’re live on Product Hunt

Loomal gives AI agents an identity — email, credentials, 2FA — all via MCP. An upvote today would mean the world.
