For people who build with AI

Stop pasting API keys into chat.

Store a key once. Push it into Vercel, GitHub, Supabase, or GoHighLevel in one click. Let your AI use it without ever seeing it. Encrypted in your browser, so we can't read it either.

Founding price for the first 200. One email when it's ready. No spam.

  • Zero-knowledge by default
  • One-click push to env
  • Open crypto core
Live demo · runs on your device Nothing is sent

What our server would store

AES-256-GCM · WebCrypto · key never leaves this tab
pasted sk-live into a chat window.env (3).txt in Downloadssame OpenAI key in four appsrotated a key, forgot two placestexted a Stripe secret to a contractorservice role key in a public repoasked the AI to read your .envSlack DM: 'here's the password'pasted sk-live into a chat window.env (3).txt in Downloadssame OpenAI key in four appsrotated a key, forgot two placestexted a Stripe secret to a contractorservice role key in a public repoasked the AI to read your .envSlack DM: 'here's the password'
How it works

Three moves. Then you stop thinking about keys.

  1. 01

    Store it once, as a bundle

    Pick a service. Supabase gives you five fields. GHL gives you four. OpenAI gives you one. Each field already knows how private it is. Names are built for you.

  2. 02

    Push it where it runs

    One click puts the right env vars into Vercel, GitHub Actions, Supabase, or Cloudflare with the right names. Rotate once, every app updates.

  3. 03

    Let your AI use it, not see it

    Flip a bundle to the agent tier. Your project gets one MCP endpoint. Claude or Cursor can add a GHL contact or open a GitHub issue. The key never shows up in the chat.

Product previewSquint / Supabase

Supabase bundle

Shared with 2 projects · rotated 12 days ago

  • url https://xyz.supabase.co plain
  • project_ref wpaovtwz… plain
  • anon_key eyJhbGciOi… low
  • service_role_key •••••••••••••••• locked
  • db_password •••••••••••• locked

Push to Vercel

squint-web · production + preview

  • NEXT_PUBLIC_SUPABASE_URL verified
  • NEXT_PUBLIC_SUPABASE_ANON_KEY verified
  • SUPABASE_SERVICE_ROLE_KEY verified
  • SUPABASE_PROJECT_REF verified
  • SUPABASE_DB_PASSWORD verified
Integrations

Your stack, on day one. More as you ask.

Solid means it ships at launch. Dashed means it is planned and the waitlist decides the order. Missing yours? Tell us.

Push keys into

One click puts the right env vars where your code runs.

At launch

VercelGitHub ActionsSupabaseCloudflare WorkersGoHighLevel

Coming next

RenderRailwayNetlifyFly.ioAWS Secrets ManagerDocker / .env export

Let your AI act in

The vault makes the call. The agent gets the result, never the key.

At launch

GoHighLevelGitHubSupabase

Coming next

Cloudflare DNSStripeAirtableResendVercelNotionSlackGoogle Search Console

Works with

One endpoint per project. One line to paste into your AI tool.

At launch

ClaudeClaude CodeCursorCodexCoworkAnything that speaks MCP

Coming next

n8nMakeZapierWindsurfChatGPT

claude mcp add vibers-vault https://…/api/mcp/<project>

Where you build

App builders that hold your keys for you. We want to hand them over safely.

Coming next

LovableBase44BoltReplitv0

Lovable apps run on Supabase, so the Supabase push already covers most of that today.

Two tiers. Your choice, per key.

Zero-knowledge by default. Agent-ready when you say so.

Every other tool makes you pick one. A vault your AI can use, or a vault nobody but you can open. We built both, and you flip between them one bundle at a time.

Sealed · default

Only people can open it.

  • Encrypted in your browser with your master password.
  • Our server stores scrambled text and cannot read it. Ever.
  • Push to Vercel and GitHub still works. It runs in your browser too.
  • Registrar logins, DB passwords, Stripe secrets live here.

Agent · opt in

Your AI can use it. Not read it.

  • You re-enter your password to flip a bundle. We log it.
  • Our server holds this key so it can act while you sleep.
  • Claude asks. The vault makes the call. Claude gets the result.
  • Read actions on. Write actions off until you turn them on.

The honest part: the agent tier is not zero-knowledge. It cannot be, or nothing could run unattended. That is why it is off by default and per key, and why the switch has a warning on it.

Everything else makes you pick two.

Agent gateways can act for you but can read your keys. Password managers are sealed but cannot push or act. A .env file is a text file.

What you get The Vibers VaultAgent gatewaysPassword managersA .env file
Encrypted before it leaves your browser YesNoYesNo
Pushes keys into Vercel, GitHub, Supabase YesNoNoNo
Your AI can use a key without seeing it YesYesNoNo
One key shared across many projects, rotated once YesNoNoNo
Burn-after-read share links YesNosomeNo
No engineer required YesNoYesYes
Security, in plain words

Built for people who read the code.

Vibe coders get a vault that just works. Real programmers get something to inspect. Both get the same promise.

Encrypted where you are
AES-256-GCM in the browser. Your master password never leaves your device. We store scrambled text and nothing that can unscramble it.
Proven, not promised
The database role our server uses has no permission to read sealed data. A test proves it fails. The core code will be public so you can read it.
A recovery kit, not a reset link
You get a printable recovery key on day one. Lose both and nobody can open your vault. That is the trade for nobody being able to open your vault.
Every action logged
Each push, share, and agent call lands in a hash-chained log. Edit one row and the chain breaks. You can verify it yourself.

Joey Zoccali

Founder. Builds with Claude every day.

Why this exists

I run my business on AI tools. By early 2026 I had keys for GoHighLevel, Supabase, Vercel, and Anthropic scattered across apps, .env files, and chat windows. I could not tell you which app used which key.

So I built a vault for myself. It works, but it was built by one guy for one guy. The Vibers Vault is the version I wish I'd had on day one, built for everyone who ships with AI and does not want to become a security engineer to do it.

Questions? Email me. hello@thevibersvault.com

Security is never the upgrade.

Every plan is zero-knowledge. You pay for room and for letting your AI in. Planned pricing. Waitlist gets the founding rate.

Free

$0forever

Enough to stop pasting keys into chat.

  • 10 bundles
  • 1 project
  • Push to Vercel, GitHub, Supabase, Cloudflare
  • Share links
  • Health checks
Join the waitlist

Pro

$12per month

For the builder with a few apps and one AI that needs keys.

  • Unlimited bundles
  • 10 projects
  • 3 agent connections
  • Audit log
  • Everything in Free
Join the waitlist

Team

$39per month

For a small team that shares keys without sharing a password.

  • Unlimited projects
  • 10 people, each with their own key
  • Unlimited agent connections
  • Everything in Pro
Join the waitlist
Questions

Ask the hard ones.

Can you read my keys?

No. Keys are encrypted in your browser with a master password that never leaves your device. Our server only stores scrambled text. If our database leaked, your keys would still be safe.

Then how can my AI use a key?

You choose. By default every bundle is sealed and only people can use it. You can move one bundle to the agent tier, which lets our server use that key to make a call for your AI. The AI gets the result, never the key. You see a plain warning before you flip it.

What if I lose my master password?

You get a recovery kit when you sign up. Print it or save it. It can unlock your vault if you forget the password. Without either one, nobody can open your vault, including us. That is the point.

Which platforms can it push keys to?

At launch: Vercel, GitHub Actions, Supabase, and Cloudflare Workers. More come as people ask.

Which AI tools work with the agent tier?

Anything that speaks MCP. Claude, Claude Code, Cursor, Codex, and Cowork all do. You get one endpoint per project and one setup line to paste.

Is this open source?

The encryption core and the MCP server will be published so anyone can read them. The hosted service is what you pay for.

When does it launch?

We are building it now. The waitlist gets in first and gets the founding price. No spam, one email when it is ready.

Founding price for the first 200.

Lock it in for life. One email when the doors open. No spam, ever.

Founding price for the first 200. One email when it's ready. No spam.