Your API keys, sealed in Claude CMS Vault
Connect Stripe, Shopify, Google, Royal Mail and more. Every key and token is encrypted the moment you paste it — Claude can use them to do the work, but it can never read them back, and neither can anyone holding just your database.
The fastest way to leak a secret is to build like everyone else
Most quickly-built apps handle credentials the dangerous way: an API key pasted straight into the source, committed to a Git repo, or dropped in a plaintext config file or a database column. A single leaked Stripe key or Google refresh token is durable access to real money and real accounts — often for weeks before anyone notices. Claude CMS was built so you never have to touch that problem. You paste a key once; the Vault does the rest.
Encrypted at rest, used without being seen
Four properties, each verifiable rather than promised.
1 Encrypted the moment it arrives
Every secret is sealed with AES-256-GCM — authenticated encryption with a fresh random IV per value, so a stored key is both unreadable and tamper-evident. Nothing sensitive is ever written to the database in the clear.
2 The key lives apart from the data
The 256-bit master key sits in a file above the web root — unreachable by URL and outside the database entirely. A stolen database dump is just a wall of ciphertext: an attacker would need your database and your server filesystem, not one of them.
3 Claude can use it, never view it
When Claude acts on a connected account — posting to LinkedIn, updating Shopify orders, sending email — the secret is decrypted server-side to make the call. Claude itself only ever sees the sealed value, never the key. It can do the work without ever holding what unlocks it.
4 Never shown again, always audited
Once you paste a secret it is never redisplayed — your Connections panel shows only a tick and the date it was provided. Every connect and disconnect is written to an audit log with the account, provider and time. The value itself is never logged.
One vault, every credential your site and store rely on
OAuth connections and pasted API keys alike are sealed the same way — whether Claude connected them for you or you deposited them in your Connections area.
What people ask about the Vault
Can Claude see my API keys?
No. Claude can act through your connected accounts, but each secret is decrypted server-side only, at the moment a call is made. Claude never receives the raw key — it only ever sees the sealed, encrypted value — and once you paste a key it is never shown again, to Claude or anywhere in your dashboard.
How are the keys encrypted?
With AES-256-GCM — authenticated encryption with a unique initialisation vector per value, so stored secrets are unreadable and tamper-evident. The 256-bit master key is kept in a file above the web root, separate from the database, unreachable over the web.
What happens if the database is breached?
A database dump yields only encrypted ciphertext. Without the master key — which lives on the server filesystem, not in the database — none of it can be decrypted. Compromising the data means compromising two separate systems, not one.
Can I remove or replace a key?
Any time, from the Connections area of your account. Enter a new value to replace one, or disconnect to remove it. Where the provider supports it — Google app passwords, for example — you can also revoke the credential at source so it can never be used again.
Do I need to be technical to use it?
No — that is the point. You paste a key once; Claude and your website use it from then on. You never wire it into code, commit it to a repo, or manage a secrets file. The dangerous parts are handled for you.
Connect your stack without the risk
Bring the platforms you already use — payments, shipping, email, CRM and analytics — and let Claude run them from one conversation. Every credential sealed in the Vault.