Team vault, Secure Send / Receive, Shared2FA, AI-safe MCP/CLI

One workspace for passwords, client handoffs, shared 2FA, and AI agents.

SecretSeal brings a 1Password-style team vault, Secure Send / Receive, Microsoft Authenticator-style Shared2FA approvals, and MCP/CLI controls into one workspace so operators can store, exchange, approve, and automate credential access without exposing secrets in email, chat, or AI sessions.

Current completion audit

Status: not-complete. Sell the proven operating loop now; keep paid billing, native distribution, and live agent runtime proof visible until external handles exist.

Open proof

5

Proven

2

Partial

1

Blocked

Proof gates still required

  • Run npm run launch:local-proof so aggregate local proof is current; this local proof does not replace external handles.
  • Run /launch-proof and npm run launch:proof-pack so the aggregate proof pack stays current.
  • Run the /billing-readiness Stripe proof drill and record real checkout, customer portal, webhook reconciliation, live non-local workspace reconciliation, and STRIPE_VERIFIED_AT proof handles.
  • Run /mobile-devices Authenticator parity drill attach physical iOS and Android push plus biometric approve/deny and signed code-render receipt proof, signed macOS package, notarization, distribution proof, and SECRETSEAL_NATIVE_VERIFIED_AT.
  • Attach signed macOS package, notarization, and distribution proof from the native operator sequence.
  • Run /settings live-agent proof drill, configure public production HTTPS SECRETSEAL_API_URL, secret-managed SECRETSEAL_API_KEY reference, live wrk_... SECRETSEAL_WORKSPACE_ID, and production/live SECRETSEAL_ENVIRONMENT; obtain the opaque receipt issued by the successful real production safe metadata-only run and record the non-secret agent-runtime proof handle before live AI use.

Stripe handles

  • STRIPE_VERIFIED_CHECKOUT_SESSION_ID
  • STRIPE_VERIFIED_PORTAL_SESSION_ID
  • STRIPE_VERIFIED_WEBHOOK_EVENT_ID

Native handles

  • SECRETSEAL_IOS_PUSH_RECEIPT_PROOF
  • SECRETSEAL_MACOS_NOTARIZATION_PROOF
  • SECRETSEAL_NATIVE_VERIFIED_AT

AI runtime handles

  • SECRETSEAL_API_URL
  • SECRETSEAL_WORKSPACE_ID
  • agent-runtime:<host>:workspace-<hash>:run-<opaque-production-receipt>

Vault

1Password-style team records

Web proof green

Send / Receive

Expiring client handoffs

Browser proof green

Shared2FA

Web approvals green; native proof pending

Partial native parity

AI access

MCP/CLI metadata and exchange ops

Handoff ready; live proof pending

Store

Workspace vault records for passwords, API keys, recovery codes, secure notes, and Shared2FA seeds.

Exchange

Secure Send / Receive handoffs keep client secrets out of email, chat, tickets, and unmanaged forms.

Approve

Shared2FA approvals keep authenticator access auditable while native proof gates stay visible.

Automate

MCP and CLI expose metadata, readiness, rotation, import, and Secure Send / Receive attention queues without plaintext by default.

Shared2FA operations
metadata safe

Authenticator records

Fast team access with review and rotation context.

NetSuite Production

ops@client.example

18s

Approval pending

Owner unlock required

Stripe Admin

finance@company.example

09s

Reviewed

Rotation in 30 days

SolBox

theo@solbox.it

24s

Metadata only

Code hidden by policy

Agent request

$ secretseal exchange ops-plan --workspace ops

activeSends: 4, openReceives: 2

$ secretseal totp ops-plan --workspace ops

rotationDue: 3, reviewDue: 5

$ secretseal vault request-reveal netsuite

approval_required: owner

Device unlock

WebAuthn protected

MCP policy

Scoped metadata first

Exchange ops

Handoff queues

Operators

Run client access without inbox archaeology.

Store durable credentials, collect inbound secrets, and prove who touched what from one workspace.

Security leads

Keep Shared2FA out of personal phones.

Use approval queues, review dates, and native approval gates while seeds stay sealed.

AI-enabled teams

Let agents help without handing them the vault.

Expose metadata, readiness, rotation plans, and Secure Send / Receive attention queues through MCP/CLI while reveal stays policy-gated.

Four products in one workspace.

SecretSeal is built for operators who need durable secrets, one-time exchanges, shared authenticator continuity, and controlled automation under the same policy model.

Team vault

Permanent encrypted records for passwords, API keys, recovery codes, secure notes, and client system credentials.

Workspace roles
Collections
Rotation tracking

Secure Send / Receive

One-time sends and receive requests move sensitive material without leaving it in email or chat.

Expiring links
Email access gates
Client-side encryption

Shared2FA

Team-controlled authenticator records for client systems that should not depend on one person's phone.

Approval queue
Review dates
No seed leakage

MCP and CLI for AI

Scoped metadata-first access for Codex, Claude Code, and trusted automation, including Secure Send / Receive attention queues without default plaintext dumping.

API-key scopes
Exchange ops plans
Audit trail

Operator workflow

Built around the way credentials actually move.

Teams do not just store passwords. They ask clients for secrets, hand credentials to colleagues, approve 2FA requests, rotate old access, and need evidence after the fact.

01

Separate the workspace

Keep client, team, and personal secrets split by workspace, role, collection, and audit history.

02

Store or exchange the secret

Use the vault for durable credentials, secure send for one-time handoff, or receive requests for inbound material.

03

Let agents work safely

AI tools can list metadata, plan rotations, create encrypted records, and request access without bypassing policy.

04

Approve, reveal, rotate

Sensitive actions stay deliberate, auditable, and ready for mobile approval as native apps mature.

AI and automation

Give agents work to do, not the whole vault.

MCP and CLI flows are designed around metadata-first access. Agents can bootstrap, list safe context, prepare encrypted imports, inspect audits, and plan rotations, while reveal and export stay policy-gated.

Review MCP access

$ secretseal agent bootstrap --client codex

safeFirstActions: status, scopes, vault_list

$ secretseal launch proof-handoff

proofTracks: billing, native parity, live MCP agent

$ secretseal vault ops-plan --before 2026-07-01T00:00:00.000Z

destructiveActionsExecuted: false

$ secretseal totp code --id netsuite

blocked: approval_required

Launch proof

Honest readiness beats vague security theater.

Public readiness contracts show what is available, what is partial, and what still needs production configuration before a buyer relies on it.

Buyer proof path 01

Sell only what is proven

Use the public readiness page to show buyers exactly which credential-handoff promises are proven, partial, or blocked: vault, Secure Send / Receive, Shared2FA, billing, native, and MCP/CLI.

Buyer proof path 02

Manage from the cockpit

Run the authenticated cockpit for workspace onboarding, API keys, billing readiness, mobile devices, audit, vault, sends, receives, and Shared2FA management.

Buyer proof path 03

Collect external launch evidence

Attach real Stripe checkout, customer portal, webhook, iOS, Android, macOS, and live agent proof handles before calling the SaaS/native/AI launch complete.

Buyer launch checklist

Show the product, keep the proof gates visible.

Open readiness
Ready to show buyers

Vault, Send / Receive, Shared2FA web approvals, management cockpit

Demo the proven operating loop: create a workspace, store a vault record, send and receive secrets, review Shared2FA approvals, and inspect audit history.

Ready with proof caveat

MCP/CLI metadata access and native approval contract

Show metadata-first AI access, Secure Send / Receive ops plans, and mobile approval flows, but keep live agent runtime and physical-device proof marked partial until external handles exist.

Do not sell as complete yet

Paid SaaS billing, native distribution, live agent runtime

Wait for real Stripe checkout, customer portal, webhook reconciliation, live non-local workspace reconciliation, physical iOS and Android biometric proof, signed macOS package, notarization, distribution, and non-secret agent-runtime proof handle before claiming launch complete.

Demoable commercial promise

A buyer can see the full operating loop today: workspace vault, Secure Send / Receive, Shared2FA approval workflow, audit trail, onboarding, and settings cockpit.

Completion proof promise

Run npm run launch:local-proof first; local proof does not replace external handles. Then run npm run launch:proof-pack, attach the missing Stripe, native-device, macOS distribution, and live-agent handles, then rerun npm run launch:completion-audit before claiming SecretSeal is complete.

Security model

Secret material stays out of the places teams forget to clean up.

TOTP seeds, generated codes, recovery codes, plaintext credentials, raw push tokens, and encrypted payloads are kept out of notifications, logs, readiness responses, and default agent output.

Replace shared spreadsheets and chat threads with workspace-scoped secret records.

Move one-time secrets and inbound client submissions through Secure Send / Receive instead of email or ticket comments.

Keep authenticator continuity for operational systems without exposing TOTP seeds in logs, notifications, or agent output.

Give AI agents useful metadata, rotation, import, and Secure Send / Receive attention queues while reveal and export paths stay policy-gated.

Show prospects the exact readiness state for billing, mobile, and MCP instead of relying on vague launch claims.

Start the proven workspace loop. Grow into paid SaaS, native approval, and live AI access.

Demo the web workspace today: vault records, Secure Send / Receive, Shared2FA approvals, audit, and MCP/CLI metadata controls. Keep paid checkout, native app release, and live MCP/CLI runtime gated until Stripe, device QA, and agent-runtime handles are captured.

SecretSeal

Zero-knowledge vault, Secure Send / Receive, Shared2FA, MCP, and CLI access.