Vault
Each machine has an encrypted credential vault (AES-256-GCM). The key is held by the platform, not stored on the machine's disk.
Agents use credentials without seeing them:
browser_loginfills and submits a login form, matching the credential by URL, and handles TOTP codes.vault_type_secrettypes a username, password or TOTP code into the focused desktop app.vault_listreturns names, URLs and usernames only.
#REST
| Method | Path | |
|---|---|---|
GET |
/api/machines/{id}/vault |
List credentials (no secrets) |
PUT |
/api/machines/{id}/vault/{name} |
Create or update: url, username, password, totpSecret, notes |
DELETE |
/api/machines/{id}/vault/{name} |
Delete |
curl -X PUT https://burrowbox.dev/api/machines/2f6aeedcd3/vault/github \
-H "Authorization: Bearer $BURROWBOX_KEY" \
-H "Content-Type: application/json" \
-d '{"url": "https://github.com/login", "username": "bot@acme.com", "password": "…", "totpSecret": "JBSWY3DPEHPK3PXP"}'
For platforms: store each customer's credentials in that customer's machine. They never leave it.