On Avibe Web chat, a lighter manual prompt can mention the missing secret as a clickable placeholder in your reply, for example $<OPENAI_API_KEY>. The user can click it and fill the secret from Web chat. This has no reason or structured prefill metadata; use vibe vault request when those are needed.
List or find existing Vault entries:
vibe vault list
vibe vault list --tag prod
vibe vault find --kind static --protection protected
vibe vault find openai --tag prod
vibe vault tags
Run a command with selected static secrets injected as environment variables:
vibe vault run --env OPENAI_API_KEY,GITHUB_TOKEN -- python script.py
vibe vault run --env GITHUB_TOKEN=GH_PAT --env OPENAI_API_KEY -- python script.py
vibe vault run --tag deploy -- ./deploy.sh
vibe vault run --skill github-release -- ./release.sh
Make an authenticated HTTP request. The credential is attached only at egress, and the agent never sees the secret:
vibe vault fetch --auth GITHUB_PAT --url https://api.github.com/user
Request approval before a protected run with an existing static secret:
vibe vault access PROD_DB_URL --skill deploy --command "run database migration" --egress "connect to production database"
For protected fetch, run vibe vault fetch; it creates the correct fetch approval request when needed.
Sign a 32-byte digest with a keypair secret. Standard keys may return the signature directly; protected keys create a browser approval request:
vibe vault sign WALLET_KEY --digest <64-hex-digest> --scheme ecdsa-secp256k1-recoverable --command "sign deployment transaction"
For more details, run vibe vault --help.