A secret is fetched when the request leaves. It is never in the file.
A variable's value can be secret://vault/kv/data/prod#token. At the send, Sonda asks your secret manager, puts the value in, and forgets it — nothing in the workspace, nothing in the team store, nothing in an export. For teams without a manager, Sonda Secrets seals each value under a key of its own, wrapped for the people allowed to read it.
The providers
One syntax, every protocol.
secret://provider/path#field works in an HTTP request, a GraphQL call, gRPC metadata, a WebSocket header, an SSE request, an MQTT password, a Socket.IO auth payload, an MCP header, an OAuth token fetch.
At send only
Resolved when the request executes, several references at once. Cached in memory for a configurable while, five minutes by default; clear the cache by hand. Never written to the workspace or the team store.
Masked on the way back
A resolved value is masked wherever it would show. The reference, not the value, is what a project carries and what a colleague receives.
Shared managers
The owner can publish a manager's address and method to the organization's catalog, so every division resolves against the same Vault without anyone typing it twice.
The team's own vault, inside the store.
For a value that has no manager to live in, and must still never be readable from the bucket.
A key per secret
An administrator stores a value. It gets a fresh 32-byte key, is sealed with AES-256-GCM, and the key is wrapped separately for each chosen reader and the administrator. Signed. A new value reseals under a fresh key.
Never on a screen
The window never receives the plaintext; it is put into the request on this computer at the send and nowhere else. Access to the repository alone decrypts nothing.
Logged
"Uses a team secret" is an activity trigger administrators can be mailed about, batched over five minutes.
Activity and mail