Skip to main content
TurenOS stores provider keys, OAuth tokens, MCP credentials, and other declared secrets in its Secret Vault.

Platform protection

Vault records are sealed with an OS-protected key. The database stores encrypted material and a key-ownership claim, not the plaintext key.

Fail-closed behavior

TurenOS does not silently downgrade to plaintext credentials. Startup or credential operations fail when native secure storage is unavailable, locked, or belongs to another OS-protected key.

Backups and migration

Copying a database to another machine does not automatically move its protected key. Export and reconnect providers through supported flows rather than copying encrypted records alone. Before resetting a vault, back up any session data you need. Removing the database or Safe Storage key can make old credentials permanently unreadable.

What the vault does not protect

Secrets deliberately placed in environment variables, shell history, source files, issue text, logs, or plain configuration remain outside the vault boundary.