Optional product · Vault
Restore protected values with Vault
Vault is for workflows that must recover an original value later. Core scanning and redaction do not require it.
01 · Vault
Capture and restore
Capture replaces a value with an opaque token. Restore succeeds only for the granted sink and path.
npm install @redact-secret/core@0.1.0-beta.13 @redact-secret/vault@0.1.0-beta.502 · Vault
Security semantics
In-memory Vault use is beta. Persistent profiles are alpha and supported only for qualified deployment combinations.
- Tokens expire and may be single-use.
- Restoration is all-or-nothing for the designated field.
- A token is not an authorization grant by itself.
const captured = await vault.capture({
value: "SYNTHETIC_REVOKED_VALUE",
sink: "support-tool",
path: "ticket.customerToken",
});
const restored = await vault.restore(captured.token, {
sink: "support-tool",
path: "ticket.customerToken",
});