Vault
Secrets for every Claude surface (Claude Code on the Mac, cloud sessions, Claude Desktop, GitHub Actions) from one master list in AWS Secrets Manager. Each project picks the keys it needs; approval is one Touch ID, Face ID or passkey.
Key metrics
Architecture
A thin wrapper over fnox with AWS Secrets Manager as the only source of truth. Hooks load each project's picked keys into Claude's commands, an MCP server lets Claude ask for a missing key, and a guard plus redactor keep values out of the transcript.
Case study
Vault
One set of secrets for every Claude surface: Claude Code on your Mac, Claude Code cloud sessions, Claude Desktop and GitHub Actions. AWS Secrets Manager is the only source of truth.
It is built for one person with many projects. Every secret lives once, in a master list. Each project picks the names it needs, and a Claude session loads only what its project picked.
@image[01.jpg]
The moment
Claude is halfway through a task and needs a key. You don't open a browser, hunt through config files or paste anything into the chat. You type one line, approve with Touch ID, and the key is there for Claude's next command. The value never appears on screen, in the transcript or on the command line. From your phone it's the same: Claude sends a link and you approve with Face ID.
What it does
- Keys by name: a project picks secrets from the master list; Claude sees them as environment variables.
- Claude can ask: an MCP server lets Claude request a missing key; you enter or pick it on a local, passkey-protected page.
- Guard and redactor: hooks keep secret values out of prompts, transcripts and command lines.
- Every surface: publish targets for Claude Code cloud sessions and GitHub Actions (OIDC).
- Web UI: projects, their keys, dates and which other projects share them.
How it works
Vault is a thin wrapper over fnox with AWS Secrets Manager as the store. Setup wires hooks, the MCP server and a mod into Claude Code, globally or for one project, and the admin AWS key sits in the macOS Keychain behind Touch ID.
Tech stack
Gallery