Credentials
Import project secrets from your vault, approve browser logins without giving passwords to agents, and keep approved fills working while you are away.
Install once with npm i -g shardflux, then use the shard command.
Bring your vault
Use credentials from hsec, 1Password, Bitwarden or macOS Keychain with your cloud agents (CLI 0.13.2+, TypeScript SDK 0.18.0+, Python 0.14.0+, MCP 0.12.0+). Your vault stays on your machine; the CLI reads only the item you select. Sign in to the vault's local CLI first, or use macOS Keychain's access prompt.
Import a named token as a project secret:
shard secrets import --from hsec GITHUB_TOKEN
shard secrets import --from 1password 'op://Private/GitHub/token' --as GITHUB_TOKEN--from accepts hsec, 1password, bitwarden and keychain. Values go directly to the project secret request;
the CLI prints metadata. Use the named secret in the workspace's secret bindings or agent configuration.
Stored encrypted with AWS KMS; only this project's workspaces can load it, and every load is logged.
Approve a browser login
Open the site in your cloud agent's browser and enable approved fill for that workspace:
shard credentials enable acme-web/mainThe agent requests a username, password or TOTP through sf-agent credential fill --site https://github.com --field password or the MCP credential_fill tool. Your attached terminal or menu bar app asks Allow once,
Always for this project or Deny. Choose the vault and item; the workspace fills the field itself and returns
{filled: true} to the agent.
Sent end to end from your vault to the workspace; Shardflux only relays encrypted bytes.
You can inspect and approve from the CLI too:
shard credentials list
shard credentials approve <request-id> --from 1password --item GitHub
shard credentials deny <request-id>Always for this project saves the permission, site, fields and vault item reference on this laptop. It lets that local approval client handle the same request again. It does not copy the password into the permission.
Keep a login available while you are away
Choose Remember for unattended use, or add --remember when approving:
shard credentials approve <request-id> --from 1password --item GitHub --remember
shard secrets log
shard credentials forget acme-web/main https://github.comRemember stores the selected website credential for that workspace and exact site origin. Subsequent approved fills work with your laptop closed. The workspace's restricted relay is renewed automatically while its issuing key or membership remains authorized. Forget revokes the remembered login; the audit log records requests and uses.
Stored encrypted with AWS KMS and filled straight into the page; agents never see it, and every use is logged.
Keep secret values out of output
Bound project secret values are redacted from exec output, terminal streams and saved command logs. The filter also covers base64 and URL-encoded forms and secrets split across output chunks. Tool-call capture sanitizes selected secret values before writing captured input and output. The browser fill result contains a status, never the credential value.
Bound secret values are redacted before command output and logs are persisted; template files remain ordinary files, including secrets you choose to save in your machine or project template.
Credential limits describes request expiry and relay renewal; the CLI, TypeScript, Python and MCP references cover automation.