Organization and team vaults
In the Vault dashboard, use Save in to choose Personal, an organization, or a team before creating an entry. The selector lists organizations you belong to and teams where you are a direct member. Personal remains the default on your own profile.
Organization members can save and read organization entries. Team entries require both organization membership and direct team membership. Team visibility, organization ownership, and membership in a parent team do not by themselves grant access to team secrets. Manage membership through the existing organization and team settings.
Each scope has separate storage. Identically named organization and team entries remain independent. Changing the selector opens another vault; it does not move or share existing entries. Leaving the organization or team removes access on subsequent requests. Deleting an organization, team, or its namespace also removes access.
Shared vaults support entry creation, metadata listing, reading, replacement, retirement, restoration, and write-outcome recovery. Access keys, OTP generation, remote setup, host-credential bindings, and encryption-key administration remain personal-only. Existing CLI and SDK commands continue to use the personal vault by default.
The API selects a shared scope with X-Vault-Scope: org:<organization-id> or X-Vault-Scope: team:<team-id> on every request. Authenticated account sessions can discover their available scope IDs and entry prefixes through GET /v1/vault/scopes. Omitting the header selects the personal vault. The server validates current membership rather than trusting the supplied scope or entry path.