detachbox
PagesGive agents your service keys with Vault

Give agents your service keys with Vault

Vault connects your boxes to Sallyport Cloud, a secure store for your API keys. Agents call your services through Sallyport, and the keys never enter the box. Risky calls wait for your tap, and every call lands in one log.

Vault, connected to Sallyport Cloud: each box has its own agent with access to its own services, and the keys never enter the box.

How it works

  • Your API keys stay in Sallyport. detachbox never sees them.
  • Each box gets its own Sallyport agent, named detachbox · <box>. It starts with no access at all.
  • You decide in Sallyport which services each box can use, and which calls wait for approval.
  • The box holds a pass that lasts one hour. The server renews it about every 50 minutes. Long-lived credentials stay on the server.
  • Claude Code, Codex, Gemini CLI and OpenCode in the box come with a Sallyport tool server set up. Your services show up to them as tools.

Access is set in Sallyport on purpose: detachbox can't grant itself your keys.

The Vault item shows in the sidebar when Sallyport is set up for the dashboard.

Connect Sallyport

  1. Open Vault from the sidebar, or press G then V.
  2. Pick Connect secure credential storage.
  3. Sign in to Sallyport and approve the connection. You return to Vault.

The page now reads Sallyport connected. Running boxes get their pass within a minute. Finish the sign-in within 30 minutes, in the same browser where you started it.

Choose what a box can use

  1. On Vault, find the box in the list.
  2. Pick Configure access in Sallyport. Sallyport opens in a new tab.
  3. Add the services this box can call and set which calls need your approval.
  4. Come back to Vault. The row reads itself again and shows how many services the box has.

A row with "No services yet" has an agent but nothing to call. A row with "No agent yet" needs Create agent first. The new agent also starts with no access.

Each box page carries the same row under Settings → Service keys.

Approve a risky call

When an agent's call needs a yes, it waits. You see it in three places:

  • Vault, under Waiting for your approval, with Approve in Sallyport
  • the Terminals list, where the tab's row shows Approve in Sallyport
  • a ping, if you turned on notifications, with Approve and Open

The approval itself happens on Sallyport's page. Once you approve, the agent's call goes through.

Watch every call

Pick Open Sallyport console on Vault to see the log of every call your boxes made, and to change keys and rules.

Box agent states

StateWhat to do
OnNothing. The box has its pass
Starts with the boxStart the box. The pass arrives with it
No agent yetPick Create agent
Paused in SallyportResume the agent in Sallyport. The box picks it up within ten minutes
Agent deleted in SallyportPick Create new agent when you want the box back on your services
Sallyport plan fullFree a seat or upgrade in Sallyport. The box retries every ten minutes
RetryingNothing. The box tries again in a minute

Disconnect Sallyport

  1. On Vault, pick Disconnect.
  2. Confirm with Disconnect Sallyport.

Every box loses its service pass at once. Connecting again brings back the same box agents and their rules.

If Sallyport ends the connection on its side, Vault shows Reconnect Sallyport. Your boxes have no service keys until you reconnect.

Clones and Vault

A clone does not carry Sallyport access. The copy connects its own.

More on keeping keys out of the box: /features/vault.