Vault
Store encrypted files for retrieval from another device or application. Encrypt the content in your client before uploading it; this endpoint accepts already-encrypted bytes, not a vault password.
Two interfaces, one vault. The endpoints below are the underlying API. Use the dashboard’s tabs: the browser client for adding and fetching secrets with one vault password, and the vault inventory for listing, relabelling, and deleting what's already stored (metadata only, never decrypts). Both surfaces, the SDK, the CLI, and the MCP server all read and write the same items via these endpoints.
POST /api/vault/store17 lines
POST /api/vault/store
{
"label": "Main wallet backup",
"encryptedData": "aabbccdd...hex",
"iv": "1122...hex",
"salt": "3344...hex"
}
201 { "id": "vi_abc123..." }
GET /api/vault/list
200 { "items": [{ "id", "label", "size", "created_at" }], "count": 1 }
GET /api/vault/:id
200 { "id", "label", "encryptedData", "iv", "salt", "size", "created_at" }
DELETE /api/vault/:id
200 { "deleted": true }Free stores 25 items and Team stores 10,000; Enterprise capacity is agreed in the contract. Maximum item size is 1MB. See current limits.
Managed Vault API
Manage named collections of encrypted items with their own inventory and activity records. This is a separate API from the standard vault; available on Team, with Enterprise deployment details agreed in the contract. The region field is stored metadata, not proof that the item is hosted in a selected region.
POST Create vault
POST /api/managed-vault
{ "label": "Production keys" }
201
{ "id": "mv_abc123...", "tier": "business", "max_items": 10000 }
The tier field here is an internal managed-vault capacity label derived from your API key tier; it is not one of the public pricing tiers. It only governs managed-vault item limits.
GET List vaults
GET /api/managed-vault
200
{ "vaults": [...], "count": 2 }
POST Store item
POST /api/managed-vault/:vid/items
{
"label": "Stripe live key",
"encryptedData": "aabbcc...",
"iv": "001122...",
"salt": "334455...",
"region": "eu-west" // optional, default eu-west
}
201
{ "id": "mvi_def456..." }
GET List items
GET /api/managed-vault/:vid/items
200
{ "items": [{ "id": "mvi_...", "label": "...", "size": 256, "region": "eu-west", "created_at": ... }], "count": 5 }
GET Get item
GET /api/managed-vault/:vid/items/:iid
200
{ "id": "mvi_...", "label": "...", "encryptedData": "...", "iv": "...", "salt": "...", "size": 256, "region": "eu-west", "created_at": ... }
DEL Delete item
DELETE /api/managed-vault/:vid/items/:iid
200
{ "deleted": true }
GET Audit log
GET /api/managed-vault/:vid/audit
200
{
"entries": [
{ "action": "item.store", "resource": "mvi_abc123", "ip": "...", "timestamp": ... }
]
}