for agents/docs/llms.txtv0.7.39 · 10 Oct 2026

Home / Docs / Vault key management

Vault key management: where each key lives, and how it travels

A vault is encrypted in the client, so the server never holds a key and the key is the whole question: whoever holds it holds the vault. This page is the reference for sgit-ai v0.20.0: each kind of credential, where it should be kept, how a key travels without entering a chat, how to give one to an agent, and how to rotate one. The reasoning and the roadmap are in the article Where the vault keys live.

Why this page exists, with the date on it. On 10 October 2026 a reader asked where the keys of the vaults that temporary agent sessions write to are managed. The docs explained what each credential can do (vault credentials) and how to hand a key to a registry (send a vault key), but nowhere said where keys should live. This page is that answer.

Each credential, and where it belongs

CredentialCanKeep it inPublish?
Vault key
sgit_private_vault_<passphrase>:<vault_id>
Read and write the vault, and derive everything belowA password manager, for keys a person holds. A registry vault, for keys agents create. The working session that needs it, for as long as it needs itNever. Not in a page, a repository, a commit message, an issue, a log or a chat
Read key
sgit_public_read_<read key>:<vault_id>
Read every file and every commitAnywhere you would put the content itselfYes, on purpose, under the public prefix. Check it with check_credential.py first
Write keyPush, and configure append lanes with the access tokenDerived when needed (sgit vault derive-keys); nowhere on its ownNever
Append tokenWrite to one lane, blindThe one sender it was issued to, one token per senderNever. Retire it once it has appeared anywhere durable
Enumeration keyList, fetch and mark lane messages processedThe vault owner, beside the vault keyNever
PKI private keyDecrypt what was sealed to you; signThe machine or vault that generated it (sgit pki keygen)Never. Publish the public bundle (sgit pki export) instead
SG/Send access tokenUse a server: create, push, configureThe environment of the sessions that push, as narrowly as the platform allows (see below)Never

How a key travels

Giving a key to an agent

An agent needs three things to work with a vault: the key, sgit, and network access to the API host (or a server in its own network: self-hosting). The key is the hard part, because agent platforms do not have secrets per session.

Rotation and retirement

On one machine

sgit vault add <alias>, sgit vault list, sgit vault show <alias> and sgit vault remove <alias> keep keys under aliases on one machine. That is convenient on a laptop. It is not a backup: an ephemeral container loses it with everything else when it is reclaimed, so a key that matters is also in the registry or a password manager.

What comes next

Integrations with password managers (the open call), the passkey-unlocked keyring of secrets.sgit.ai, PKI for sharing without shared secrets, and decryption that happens out of band. Statuses are in the article.

Checked against sgit-ai v0.20.0 and the live API documentation of send.sgraph.ai (v0.32.4) and dev.send.sgraph.ai (v0.33.69) on 10 October 2026.