MASAKA / Security / Secrets & vaults
Security

Send a value
without revealing it.

Credentials and vault items are encrypted at rest, owner-scoped, and usable only on their exact HTTPS hostname.

Secret resources

CredentialFocused login valueUp to 4,000 characters with exact hostname binding.
VaultReusable protected valueUp to 8,000 characters, project-scoped and hostname-bound.
Managed AuthProfile + credentialBinds reusable login state and secret to one hostname.

Server-mediated use

A controlled session sends a credential or vault command with the owned record ID. The worker checks the current page is HTTPS and exactly matches the saved hostname before typing the decrypted value.

What lists never return

  • Plaintext secret values
  • Encryption keys or encrypted blobs
  • Full proxy URLs containing credentials
  • Profile archive bytes