What is AgentSecrets?
The Zero-Knowledge Difference
How AgentSecrets Works
Installation
Quick Start
Migrating from .env Files
Migrating from Vault / AWS
Migrating from dotenv-vault
Production Checklist
Credential Exposure
What Zero-Knowledge Means
The Proxy Model
The Three-Layer Model
Environments
Agent Identity
Storage Modes
The No get() Principle
Secret-Level Policies
Cloud Overview & Architecture
The Dual-Engine Model
Cloud Resolver Data Plane
Workload & Agent Tokens
Egress Allowlists & Audit Streams
Cloud REST API Reference
Account (init / login)
Server & Self-Hosting (server)
Docs
Shell Autocompletion
Keychain Auth
Secrets
Environments
Credential Proxy
env Injection
Workspaces & Teams
Projects
Agent Identity
Audit & Governance
Integrations Overview
Claude Desktop
Cursor
OpenClaw
HTTP Proxy (Any)
LangChain (Soon)
CrewAI (Soon)
CI/CD Pipeline
SDK Overview
Python SDK
Python API Reference
Python SDK Manual Testing
JavaScript SDK (Soon)
Ecosystem Overview
Zero-Knowledge MCP Server
Server Overview
5-Layer Architecture
Self-Hosting Guide
Authentication & Keys
Workspaces & Teams
Projects & Scope
Environments
Secrets & Sync Protocol
Agent Identity Resolution
Telemetry & Metrics Engine
Audit Log Sync
API Endpoint Reference
Security Overview
Anti-Impersonation & Process Verification
Encryption Model
Zero-Knowledge Sync
Proxy Security Layers
Threat Model
OWASP Top 10 Mitigation
Security FAQ
Third-Party Audit
Reporting Vulnerabilities
Guides Overview
Building on the SDK
Stripe Integration
OpenAI Integration
Multi-Agent Setup
Onboarding Team
CI/CD Pipeline
Publishing ZK MCP
Rotating Credentials
Auditing Team Activity
Dev to Production
Kubernetes Deployment
Monorepo Setup
Production Proxy Hardening
vs .env Files
vs HashiCorp Vault
vs AWS Secrets Manager
vs dotenv-vault
vs Infisical
When Not to Use
Proxy Not Starting
Proxy Not Resolving
Domain Blocked
Sync Conflicts
MCP Not Connecting
Session Token Errors
Proxy Session Authorization
Keychain Storage & Backends
SSRF & Destination Rules
Installation Issues
Error Codes Reference
Frequently Asked Questions
v3.1.x
v3.0.0
v2.1.0
v2.0.0
v1.4.0
v1.3.x
v1.2.0
v1.1.x
v1.0.x
Server & BackendServer Overview

Server Overview

agentsecrets-server is the asynchronous coordination backend for the AgentSecrets ecosystem. It coordinates multi-client secret synchronization, team key exchange, and platform telemetry without ever holding, seeing, or processing plaintext credentials.

The server operates as an untrusted coordinator: it stores ciphertext blobs, verifies workspace memberships, and routes encrypted payloads between authorized clients.


Core Responsibilities

┌──────────────────────────────────────┐ │ CLI / SDK / ZK MCP │ <- Local Machine (Encrypts / Decrypts) └──────────────────┬───────────────────┘ │ HTTPS REST API (Ciphertext Only) ┌──────────────────────────────────────┐ │ agentsecrets-server │ <- Blind Coordinator & Ciphertext Host └──────────────────┬───────────────────┘ ┌──────────────────────────────────────┐ │ PostgreSQL / Redis Cache │ <- Double-Envelope Encrypted At Rest └──────────────────────────────────────┘

The server manages five core domains:

DomainResponsibilitySecurity Invariant
Ciphertext StorageBulk secret upsert, versioning, and environment-scoped retrievalCiphertext is encrypted client-side (AES-256-GCM) and double-wrapped at rest (Fernet). The server holds no decryption keys.
Workspaces & AccessWorkspace membership, role enforcement (Owner, Admin, Member), and domain allowlistsMembership updates exchange workspace keys encrypted under recipients' X25519 public keys.
Agent IdentityAgent registration, token issuance, and capability allowlist scopingEnforces granular HTTP method and domain bounds per agent token.
Audit Log IngestionCentralized collection of client proxy access logsIngests SHA-256 hash-chained records with redacted credential fields.
Telemetry & MetricsDaily anonymous client snapshot ingestion and platform analyticsRegex sanitization strips all file paths, usernames, and binary names from execution logs.

The Zero-Knowledge Guarantee

Traditional secrets managers operate as trusted vaults: the server receives plaintext over TLS, holds master decryption keys, and logs access. A server compromise exposes every secret in storage.

agentsecrets-server is architecturally blind:

  1. Client-Side Encryption: Secrets are encrypted locally via AES-256-GCM before transmission. The server receives base64-encoded ciphertext blobs.
  2. Asymmetric Key Wrapping: Workspace encryption keys are wrapped using recipients' public keys (X25519 / NaCl SealedBox). The server stores sealed envelopes it cannot decrypt.
  3. Double-Envelope Protection: When persisting records to PostgreSQL, the server applies an outer Fernet encryption layer (ENCRYPTION_KEY). Decrypting this database layer only yields the client-side AES ciphertext.

Architecture at a Glance

The backend is built in Python with a strict 5-layer separation:

  • Controllers (views.py): Thin HTTP adapters (< 25 LOC per route) handling validation and serialization.
  • Selectors (selectors.py): Pure read queries, prefetching, and in-memory caching with zero side effects.
  • Services (services.py): Atomic business operations wrapped in database transactions (transaction.atomic()).
  • Schemas (schemas.py): Strict Pydantic v2 data models with extra="forbid".
  • Models (models.py): PostgreSQL tables with UUID primary keys and composite indexing.

For a deep dive into the implementation details, see 5-Layer Architecture.

Was this helpful?
Thanks for your feedback!
Your feedback helps us improve the platform.