TrustPortDocs
In the dashboardKey Vault & Secrets

Store a secret

  1. Choose Create

    Give it a name your team will recognise, like stripe_secret_key, and pick the environment it belongs to: production, staging or development.

  2. Paste the value

    It is encrypted with AES-256-GCM before it is stored. The value is shown once while you create it; closing the dialog clears it from the page.

Read a secret back

Choose Reveal on the secret. Only owners and admins can reveal values; viewers can see that a secret exists but never its contents.

Encryption keys

KeyWhat it is
TrustPort-managed keyEncrypts your stored secrets with AES-256-GCM. TrustPort manages and rotates it.
Your own keys (BYOK records)A register of the AWS KMS, Google Cloud KMS, Azure Key Vault or HashiCorp Vault keys your workspace uses, with provider and key ID.
Registering your own key records it for your inventory. TrustPort doesn't call your key management service and doesn't use that key to encrypt Vault secrets.

Remove a secret

Delete secrets you no longer use. Deleting can't be undone, so rotate the secret at its source first.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.