The Vault keeps logins, API keys, licence codes and two-factor secrets for your clients and your own team, linked to the company they belong to.

How secrets are protected

  • Every vault item is private: only its creator and people it is shared with can see it.
  • The secret value is not a field of the record. It is stored separately, encrypted per workspace (AES-GCM).
  • Revealing a secret or a two-factor code is only possible for a signed-in member, acting as themselves, in the Hermios app. API keys, OAuth tokens, apps, impersonated sessions and the API playground cannot reveal, set or clear secrets.
  • Every reveal, change and removal is logged before the value is returned, and the value is not returned if logging fails. Open the item to see its access history.
  • Reveals are limited to 30 per minute per person.
  • Items can carry a rotate by date, and Hermios reminds you when a secret is due for rotation.

Through the API

vaultItem / vaultItems behaves like any other object for its non-secret fields: name, category, url, username, notes, files, company, rotateBy, and the read-only hasSecret.
A key only sees items shared with the key’s role. Secret values are never returned by the API.