How secrets are protected
- Every vault item is private: only its creator and people it is shared with can see it.
- The secret value is not a field of the record. It is stored separately, encrypted per workspace (AES-GCM).
- Revealing a secret or a two-factor code is only possible for a signed-in member, acting as themselves, in the Hermios app. API keys, OAuth tokens, apps, impersonated sessions and the API playground cannot reveal, set or clear secrets.
- Every reveal, change and removal is logged before the value is returned, and the value is not returned if logging fails. Open the item to see its access history.
- Reveals are limited to 30 per minute per person.
- Items can carry a rotate by date, and Hermios reminds you when a secret is due for rotation.
Through the API
vaultItem / vaultItems behaves like any other object for its non-secret fields: name, category, url, username, notes, files, company, rotateBy, and the read-only hasSecret.