| Key | Kind | Health | Rotation | Age | Last used | Leak cover | Actions |
|---|
What is covered, and what is not
loading
Fast lane watches the PowerShell console history and the screenshot folder, the two places a secret lands seconds after a human mistake. The full sweep adds Claude and Codex transcripts, every file under Coding changed in the last 24 hours, and the staged diff of every git repo, so a secret is caught before it is committed.
Open findings
Ignore rules
| Profile | Kind | Size | Modified | Logins | Label | Actions |
|---|
Which Chrome profile should I use
Ask before launching. Never invent a new user_data_dir, and never ask the owner to log in again when a labelled profile already exists.
GET http://127.0.0.1:8765/api/profiles/for?service=acme-portal
200 {"found": true,
"user_data_dir": "C:\\Users\\demo\\.browser-profiles\\acme-portal",
"logged_in_domains": ["acme-portal.example"],
"in_use_right_now": false,
"rule": "One profile, one owner."}
200 {"found": false,
"reason": "no registered profile for that service",
"what_to_do": "Ask the owner. Do NOT create a new user_data_dir."}
I think I leaked a secret
Report it the moment you suspect it. Never send the value itself.
POST http://127.0.0.1:8765/api/leak-report
Content-Type: application/json
{"key_name": "demo-provider-key",
"where": "chat transcript",
"detail": "pasted into a command line and screenshotted"}
This raises the same loud banner and the same Telegram alert as a scanner finding.
Provider reference
Every rotation page, auth header shape, read only verify endpoint and token format the vault knows about lives in docs/PROVIDERS.md. Read that before working against one of these APIs.