Your vault, from this browser
Paste the owner token (from ~/.vault/config.json, or vault init). It stays in this browser only.
Paste the owner token (from ~/.vault/config.json, or vault init). It stays in this browser only.
Email addresses agents were given instead of yours. Each was made for one recipient; mail to it is forwarded to …. Revoke one and mail to it bounces.
Accounts Vault holds for you. An agent never gets the sign-in: it asks for one named operation, you read it as a sentence, and Vault makes the call as you. Reading and acting each have a policy: ask waits for you, auto goes ahead and is logged, never refuses.
Sites you signed into with your own hands. Vault keeps the session (cookies), sealed, one per site, and opens the site as you when an agent asks to read a page — or, only on a site you put in the act tier, to click and type. You read every request as a sentence first unless you set a policy to auto. This is not read-only by construction: a session can do what you can do on that site, so choose sites you'd let a careful assistant use. Nothing you type in the live view is stored, logged or shown to any model.
The live view lasts up to 10 minutes. Sign in, land on the page agents should start from, then tap Keep this session.
What happens when an agent asks for a fact of each class. ask waits for you here; draft means the agent prepares and you send; auto grants within scope and time; never refuses. The strictest fact in a request governs it. Presence can't be loosened.
What the phone app and the CLI sign in with. Anyone holding it is you to this vault: reveal it only to paste it into your own app.
••••••••••••••••••••••••••••••••Everything as JSON: facts, policies, agents, grants, receipts.
Removes every fact, grant, receipt and token. Agents connected to it stop working at once. Export first.