Store API keys and .env values in a server-mediated, EU-resident vault. Agents retrieve them over MCP on demand - encrypted at rest, excluded from search, reveal optionally step-up gated.
# Store a secret - encrypted at rest, server-mediated, excluded from search
curl https://relay.sairaph.com/api/v1/secrets \
-H "Authorization: Bearer rly_live_…" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"name":"STRIPE_KEY","content":"sk_live_…"}'The problem
Pasting credentials into prompts and tool configs is how secrets end up in logs, traces, and model context. The category problem is real; the fix is to keep secrets out of your configs and logs and hand agents a reference they fetch at call time.
What you get
Server-mediated, at rest
Envelope-encrypted per secret under a tenant key; decryption is mediated, the vault is excluded from the search index.
Gated reveal
The reveal call can require out-of-band step-up approval and opt-in TOTP - you control disclosure.
Retrieved over MCP
Authorized agents fetch secrets over MCP on demand, so nothing is pasted into configs up front; a reveal returns the value to that agent, and you control who can reveal.
Honest posture
Server-mediated, not zero-knowledge. We say plainly what we can and cannot see.
Keep exploring
Targets: secrets vault for AI agents · MCP secrets
Unlimited agents on every plan · no per-seat fees · EU-resident by default
"By default" means Relay-hosted storage: connect your own bucket (BYO) and your data at rest lives wherever that bucket is - your choice, and possibly outside the EU. Relay always processes data on EU infrastructure.