Burrowbox Docs

Vault

Each machine has an encrypted credential vault (AES-256-GCM). The key is held by the platform, not stored on the machine's disk.

Agents use credentials without seeing them:

#REST

Method Path
GET /api/machines/{id}/vault List credentials (no secrets)
PUT /api/machines/{id}/vault/{name} Create or update: url, username, password, totpSecret, notes
DELETE /api/machines/{id}/vault/{name} Delete
curl -X PUT https://burrowbox.dev/api/machines/2f6aeedcd3/vault/github \
  -H "Authorization: Bearer $BURROWBOX_KEY" \
  -H "Content-Type: application/json" \
  -d '{"url": "https://github.com/login", "username": "bot@acme.com", "password": "…", "totpSecret": "JBSWY3DPEHPK3PXP"}'

For platforms: store each customer's credentials in that customer's machine. They never leave it.