Give agents your service keys with Vault
Vault connects your boxes to Sallyport Cloud, a secure store for your API keys. Agents call your services through Sallyport, and the keys never enter the box. Risky calls wait for your tap, and every call lands in one log.

How it works
- Your API keys stay in Sallyport. detachbox never sees them.
- Each box gets its own Sallyport agent, named
detachbox · <box>. It starts with no access at all. - You decide in Sallyport which services each box can use, and which calls wait for approval.
- The box holds a pass that lasts one hour. The server renews it about every 50 minutes. Long-lived credentials stay on the server.
- Claude Code, Codex, Gemini CLI and OpenCode in the box come with a Sallyport tool server set up. Your services show up to them as tools.
Access is set in Sallyport on purpose: detachbox can't grant itself your keys.
The Vault item shows in the sidebar when Sallyport is set up for the dashboard.
Connect Sallyport
- Open Vault from the sidebar, or press
GthenV. - Pick Connect secure credential storage.
- Sign in to Sallyport and approve the connection. You return to Vault.
The page now reads Sallyport connected. Running boxes get their pass within a minute. Finish the sign-in within 30 minutes, in the same browser where you started it.
Choose what a box can use
- On Vault, find the box in the list.
- Pick Configure access in Sallyport. Sallyport opens in a new tab.
- Add the services this box can call and set which calls need your approval.
- Come back to Vault. The row reads itself again and shows how many services the box has.
A row with "No services yet" has an agent but nothing to call. A row with "No agent yet" needs Create agent first. The new agent also starts with no access.
Each box page carries the same row under Settings → Service keys.
Approve a risky call
When an agent's call needs a yes, it waits. You see it in three places:
- Vault, under Waiting for your approval, with Approve in Sallyport
- the Terminals list, where the tab's row shows Approve in Sallyport
- a ping, if you turned on notifications, with Approve and Open
The approval itself happens on Sallyport's page. Once you approve, the agent's call goes through.
Watch every call
Pick Open Sallyport console on Vault to see the log of every call your boxes made, and to change keys and rules.
Box agent states
| State | What to do |
|---|---|
| On | Nothing. The box has its pass |
| Starts with the box | Start the box. The pass arrives with it |
| No agent yet | Pick Create agent |
| Paused in Sallyport | Resume the agent in Sallyport. The box picks it up within ten minutes |
| Agent deleted in Sallyport | Pick Create new agent when you want the box back on your services |
| Sallyport plan full | Free a seat or upgrade in Sallyport. The box retries every ten minutes |
| Retrying | Nothing. The box tries again in a minute |
Disconnect Sallyport
- On Vault, pick Disconnect.
- Confirm with Disconnect Sallyport.
Every box loses its service pass at once. Connecting again brings back the same box agents and their rules.
If Sallyport ends the connection on its side, Vault shows Reconnect Sallyport. Your boxes have no service keys until you reconnect.
Clones and Vault
A clone does not carry Sallyport access. The copy connects its own.
More on keeping keys out of the box: /features/vault.