Stop pasting API keys into chat.
Store a key once. Push it into Vercel, GitHub, Supabase, or GoHighLevel in one click. Let your AI use it without ever seeing it. Encrypted in your browser, so we can't read it either.
- Zero-knowledge by default
- One-click push to env
- Open crypto core
What our server would store
Three moves. Then you stop thinking about keys.
- 01
Store it once, as a bundle
Pick a service. Supabase gives you five fields. GHL gives you four. OpenAI gives you one. Each field already knows how private it is. Names are built for you.
- 02
Push it where it runs
One click puts the right env vars into Vercel, GitHub Actions, Supabase, or Cloudflare with the right names. Rotate once, every app updates.
- 03
Let your AI use it, not see it
Flip a bundle to the agent tier. Your project gets one MCP endpoint. Claude or Cursor can add a GHL contact or open a GitHub issue. The key never shows up in the chat.
Supabase bundle
Shared with 2 projects · rotated 12 days ago
- url https://xyz.supabase.co plain
- project_ref wpaovtwz… plain
- anon_key eyJhbGciOi… low
- service_role_key •••••••••••••••• locked
- db_password •••••••••••• locked
Push to Vercel
squint-web · production + preview
- NEXT_PUBLIC_SUPABASE_URL verified
- NEXT_PUBLIC_SUPABASE_ANON_KEY verified
- SUPABASE_SERVICE_ROLE_KEY verified
- SUPABASE_PROJECT_REF verified
- SUPABASE_DB_PASSWORD verified
Your stack, on day one. More as you ask.
Solid means it ships at launch. Dashed means it is planned and the waitlist decides the order. Missing yours? Tell us.
Push keys into
One click puts the right env vars where your code runs.
At launch
Coming next
Let your AI act in
The vault makes the call. The agent gets the result, never the key.
At launch
Coming next
Works with
One endpoint per project. One line to paste into your AI tool.
At launch
Coming next
claude mcp add vibers-vault https://…/api/mcp/<project>
Where you build
App builders that hold your keys for you. We want to hand them over safely.
Coming next
Lovable apps run on Supabase, so the Supabase push already covers most of that today.
Zero-knowledge by default. Agent-ready when you say so.
Every other tool makes you pick one. A vault your AI can use, or a vault nobody but you can open. We built both, and you flip between them one bundle at a time.
Sealed · default
Only people can open it.
- Encrypted in your browser with your master password.
- Our server stores scrambled text and cannot read it. Ever.
- Push to Vercel and GitHub still works. It runs in your browser too.
- Registrar logins, DB passwords, Stripe secrets live here.
Agent · opt in
Your AI can use it. Not read it.
- You re-enter your password to flip a bundle. We log it.
- Our server holds this key so it can act while you sleep.
- Claude asks. The vault makes the call. Claude gets the result.
- Read actions on. Write actions off until you turn them on.
The honest part: the agent tier is not zero-knowledge. It cannot be, or nothing could run unattended. That is why it is off by default and per key, and why the switch has a warning on it.
Everything else makes you pick two.
Agent gateways can act for you but can read your keys. Password managers are sealed but cannot push or act. A .env file is a text file.
| What you get | The Vibers Vault | Agent gateways | Password managers | A .env file |
|---|---|---|---|---|
| Encrypted before it leaves your browser | Yes | No | Yes | No |
| Pushes keys into Vercel, GitHub, Supabase | Yes | No | No | No |
| Your AI can use a key without seeing it | Yes | Yes | No | No |
| One key shared across many projects, rotated once | Yes | No | No | No |
| Burn-after-read share links | Yes | No | some | No |
| No engineer required | Yes | No | Yes | Yes |
Built for people who read the code.
Vibe coders get a vault that just works. Real programmers get something to inspect. Both get the same promise.
- Encrypted where you are
- AES-256-GCM in the browser. Your master password never leaves your device. We store scrambled text and nothing that can unscramble it.
- Proven, not promised
- The database role our server uses has no permission to read sealed data. A test proves it fails. The core code will be public so you can read it.
- A recovery kit, not a reset link
- You get a printable recovery key on day one. Lose both and nobody can open your vault. That is the trade for nobody being able to open your vault.
- Every action logged
- Each push, share, and agent call lands in a hash-chained log. Edit one row and the chain breaks. You can verify it yourself.
Joey Zoccali
Founder. Builds with Claude every day.
I run my business on AI tools. By early 2026 I had keys for GoHighLevel, Supabase, Vercel, and Anthropic scattered across apps, .env files, and chat windows. I could not tell you which app used which key.
So I built a vault for myself. It works, but it was built by one guy for one guy. The Vibers Vault is the version I wish I'd had on day one, built for everyone who ships with AI and does not want to become a security engineer to do it.
Questions? Email me. hello@thevibersvault.com
Security is never the upgrade.
Every plan is zero-knowledge. You pay for room and for letting your AI in. Planned pricing. Waitlist gets the founding rate.
Free
$0forever
Enough to stop pasting keys into chat.
- 10 bundles
- 1 project
- Push to Vercel, GitHub, Supabase, Cloudflare
- Share links
- Health checks
Pro
$12per month
For the builder with a few apps and one AI that needs keys.
- Unlimited bundles
- 10 projects
- 3 agent connections
- Audit log
- Everything in Free
Team
$39per month
For a small team that shares keys without sharing a password.
- Unlimited projects
- 10 people, each with their own key
- Unlimited agent connections
- Everything in Pro
Ask the hard ones.
Can you read my keys?
No. Keys are encrypted in your browser with a master password that never leaves your device. Our server only stores scrambled text. If our database leaked, your keys would still be safe.
Then how can my AI use a key?
You choose. By default every bundle is sealed and only people can use it. You can move one bundle to the agent tier, which lets our server use that key to make a call for your AI. The AI gets the result, never the key. You see a plain warning before you flip it.
What if I lose my master password?
You get a recovery kit when you sign up. Print it or save it. It can unlock your vault if you forget the password. Without either one, nobody can open your vault, including us. That is the point.
Which platforms can it push keys to?
At launch: Vercel, GitHub Actions, Supabase, and Cloudflare Workers. More come as people ask.
Which AI tools work with the agent tier?
Anything that speaks MCP. Claude, Claude Code, Cursor, Codex, and Cowork all do. You get one endpoint per project and one setup line to paste.
Is this open source?
The encryption core and the MCP server will be published so anyone can read them. The hosted service is what you pay for.
When does it launch?
We are building it now. The waitlist gets in first and gets the founding price. No spam, one email when it is ready.
Founding price for the first 200.
Lock it in for life. One email when the doors open. No spam, ever.