Skip to main content

The Secrets Vault: credentials Floxar can never read

When an AI agent runs one of your flows, some steps act on your own systems: it updates a record in your CRM, closes a ticket, or calls an internal tool. To do that, the agent needs credentials for those systems. The Secrets Vault is a safe place in Floxar to keep them, built so that Floxar itself can never read what you store.

The Vault is optional. If your team already uses a secrets manager, your agents can keep using it.

Why Floxar cannot read your secrets​

  • Encrypted in your browser. When an admin saves a credential, your browser encrypts it before it is sent. Floxar only ever receives the encrypted form.
  • A key split in two. Each secret is locked with a key that is split between you and Floxar. Floxar keeps one half; the other half stays with you, in a private key file only your agents hold. Neither half can open anything alone, so Floxar never holds a readable secret, and a breach of Floxar's storage would not expose your values.
  • Opened only by your agents. An agent you run opens a secret in memory, at the moment a step needs it, using the private key file you gave it.
  • Referenced by name. Flows and trails refer to a credential by its name, never by its value. A trail shows that a step used a credential and which version, never the credential itself.
  • Kept apart. The Vault runs separately from the rest of Floxar, with its own storage.

What you can do with it​

  • Store credentials such as API keys, passwords and tokens, each under a name your flows can use.
  • Decide which agents may use each one. Access is denied by default: an agent can open a secret only if an admin has granted it that secret, whatever the agent's role.
  • Reference credentials in flows. Authors add a credential reference to the step that needs it, naming the credential and what it is for, so the person or agent on that step knows which access the step uses.
  • Rotate, revoke and review. Replace a value with a new version, stop an agent's access, and see a log of who or what used each secret and when.

Turning it on and setting it up​

The Vault is switched on per account. If it is not available on yours yet, ask at help@floxar.com. Account admins open it from the Floxar application (Resources, then Secrets Vault), enable it for the account, and accept the Vault's terms. Only account admins manage the Vault.

  1. Create a recipient key. The key is generated in your browser. You download the private key file and confirm you have kept it; Floxar receives only the public part.
  2. Store a secret. Give it a name, a type and its value. The value is sealed in your browser before it is stored.
  3. Grant access. Choose which registered agents may open the secret, optionally until an expiry date.

For how to reference credentials in your flows well, see Working with credentials in flows. The people building those agents will find the run-time details in Using the Secrets Vault from an agent.

Good to know​

  • Keep your own copy. The Vault is a working copy for running flows, not your system of record. Keep your own copy of every credential, and back up your private key files: Floxar cannot recover a lost key or a secret sealed only to it.
  • Revoking stops future use, not past use. Removing access or revoking a secret stops agents from opening it again, but cannot recall a value an agent has already opened. If a credential may have leaked, change it in the system it belongs to.

Last reviewed: 2026-09-30