/ SONDA · ENTERPRISE

A secret is fetched when the request leaves. It is never in the file.

A variable's value can be secret://vault/kv/data/prod#token. At the send, Sonda asks your secret manager, puts the value in, and forgets it — nothing in the workspace, nothing in the team store, nothing in an export. For teams without a manager, Sonda Secrets seals each value under a key of its own, wrapped for the people allowed to read it.

8 PROVIDERS RESOLVED AT SEND 5-MINUTE MEMORY CACHE A KEY PER SECRET

The providers

VaultHashiCorp Vault with a token or AppRole, a namespace, KV v1 and v2.
CloudsAWS Secrets Manager. Azure Key Vault. Google Secret Manager.
Services1Password Connect. Doppler. Infisical.
YoursAny HTTP endpoint that answers JSON.
Sondasecret://sonda/name — the team's own vault, in the store.
/ HOW IT RESOLVES

One syntax, every protocol.

secret://provider/path#field works in an HTTP request, a GraphQL call, gRPC metadata, a WebSocket header, an SSE request, an MQTT password, a Socket.IO auth payload, an MCP header, an OAuth token fetch.

At send only

Resolved when the request executes, several references at once. Cached in memory for a configurable while, five minutes by default; clear the cache by hand. Never written to the workspace or the team store.

Masked on the way back

A resolved value is masked wherever it would show. The reference, not the value, is what a project carries and what a colleague receives.

Shared managers

The owner can publish a manager's address and method to the organization's catalog, so every division resolves against the same Vault without anyone typing it twice.

/ SONDA SECRETS

The team's own vault, inside the store.

For a value that has no manager to live in, and must still never be readable from the bucket.

A key per secret

An administrator stores a value. It gets a fresh 32-byte key, is sealed with AES-256-GCM, and the key is wrapped separately for each chosen reader and the administrator. Signed. A new value reseals under a fresh key.

Never on a screen

The window never receives the plaintext; it is put into the request on this computer at the send and nowhere else. Access to the repository alone decrypts nothing.

Logged

"Uses a team secret" is an activity trigger administrators can be mailed about, batched over five minutes.

Activity and mail
/ LOCKFLARE SONDA

Every secret manager, in the free edition.

Secrets, listed →