Skip to content
Documentation/docs/vault/
Browse documentation

Optional product · Vault

Restore protected values with Vault

Vault is for workflows that must recover an original value later. Core scanning and redaction do not require it.

01 · Vault

Capture and restore

Capture replaces a value with an opaque token. Restore succeeds only for the granted sink and path.

npm install @redact-secret/core@0.1.0-beta.13 @redact-secret/vault@0.1.0-beta.5

02 · Vault

Security semantics

In-memory Vault use is beta. Persistent profiles are alpha and supported only for qualified deployment combinations.

  • Tokens expire and may be single-use.
  • Restoration is all-or-nothing for the designated field.
  • A token is not an authorization grant by itself.
const captured = await vault.capture({
  value: "SYNTHETIC_REVOKED_VALUE",
  sink: "support-tool",
  path: "ticket.customerToken",
});

const restored = await vault.restore(captured.token, {
  sink: "support-tool",
  path: "ticket.customerToken",
});