← All work
Developer Tools · Product · 2026

Vault

Secrets for every Claude surface (Claude Code on the Mac, cloud sessions, Claude Desktop, GitHub Actions) from one master list in AWS Secrets Manager. Each project picks the keys it needs; approval is one Touch ID, Face ID or passkey.

Vault
Year
2026
Status
Product
Category
Developer Tools
Role
Architect & Lead

Key metrics

0.4
Version
936
Tests
Touch ID · Face ID · passkeys
Proofs

Architecture

A thin wrapper over fnox with AWS Secrets Manager as the only source of truth. Hooks load each project's picked keys into Claude's commands, an MCP server lets Claude ask for a missing key, and a guard plus redactor keep values out of the transcript.

Case study

Vault

One set of secrets for every Claude surface: Claude Code on your Mac, Claude Code cloud sessions, Claude Desktop and GitHub Actions. AWS Secrets Manager is the only source of truth.

It is built for one person with many projects. Every secret lives once, in a master list. Each project picks the names it needs, and a Claude session loads only what its project picked.

@image[01.jpg]

The moment

Claude is halfway through a task and needs a key. You don't open a browser, hunt through config files or paste anything into the chat. You type one line, approve with Touch ID, and the key is there for Claude's next command. The value never appears on screen, in the transcript or on the command line. From your phone it's the same: Claude sends a link and you approve with Face ID.

What it does

  • Keys by name: a project picks secrets from the master list; Claude sees them as environment variables.
  • Claude can ask: an MCP server lets Claude request a missing key; you enter or pick it on a local, passkey-protected page.
  • Guard and redactor: hooks keep secret values out of prompts, transcripts and command lines.
  • Every surface: publish targets for Claude Code cloud sessions and GitHub Actions (OIDC).
  • Web UI: projects, their keys, dates and which other projects share them.

How it works

Vault is a thin wrapper over fnox with AWS Secrets Manager as the store. Setup wires hooks, the MCP server and a mod into Claude Code, globally or for one project, and the admin AWS key sits in the macOS Keychain behind Touch ID.

Tech stack

Claude Code mod + MCP serverAWS Secrets ManagerfnoxBashSwiftPython

Gallery

Other 2026 work