SkilVault
Sign inGet started

Security & privacy

How your keys, passwords and downloads are protected, and exactly what SkilVault records about your use.

Your API keys

  • Keys are long random strings (144 bits of randomness).
  • SkilVault stores only a SHA-256 fingerprint of each key, never the key. That is why a lost key cannot be shown again.
  • Revocation is instant: the key is checked on every request.
  • Completing a password reset revokes every key on the account.

Your password and session

  • Passwords are hashed with Argon2; the plain text is never stored.
  • Every account uses two-step verification: an authenticator app, a passkey, or both, plus one-time recovery codes. A password alone never signs you in, and a password reset never removes your second factor. Manage it under Settings → Security.
  • Creating an API key asks for your second factor again if you have not used it in the last 10 minutes.
  • Sessions use a cookie that page scripts cannot read (HttpOnly), is not sent on cross-site requests (SameSite=Lax) and is marked Secure in production. Only a hash of the session token is stored, and sessions last 30 days (12 hours for administrators). Settings → Security lists your sessions and signs any of them out.
  • Repeated failed sign-ins are throttled per email and network and per account across all networks, and the sign-in and reset forms answer identically whether or not an address has an account.
  • Password reset links are single-use and expire after 30 minutes.

Skills are signed

Every published version is signed offline by the operator with a hardware key that never touches the server. The client checks the signature against the keys it was installed with — a file on your machine that the server can never change — before it reads, installs or updates anything, and then checks the pack against the signed checksum. A version can also be signed as part of a batch: one signature over a list naming each version and its checksum, which the client checks the same way. It refuses an unsigned version, a signature from an unknown key, a download that does not match, and any version older than one it has already used. So even someone in control of the SkilVault server cannot make your agent run a skill the operator did not sign. The installer prints the key fingerprints; compare them with the ones your operator publishes. Packs are built deterministically, so the same content always has the same checksum (Skill format).

Keys stay out of URLs

The client and the install command send your key in an Authorization: Bearer header, never in the address, because addresses end up in server and proxy logs. The server still accepts a ?k= parameter from older clients; the reference deployment's web server strips it from its access logs, and responses are marked Cache-Control: no-store. Use the header in your own scripts too (API reference).

Skills and your machine

A skill is a set of instructions that Claude follows on your machine, with the permissions you have given Claude. Skills are reviewed before they are published, but they are provided as-is. You can read any skill in your library first: skilvault read <name> prints it without running anything. SkilVault itself does not run skills.

What is recorded

DataWhat
AccountEmail, name (if given), password hash, plan and billing status. Card details are held by Stripe, never by SkilVault.
UsageFor each request by a key: the type (manifest fetch, download or search), the time, the skill and version for downloads, the request's IP address, and — for searches — the text of the search.
Skill usesEach time a skill is used: the skill, its version, which CLI used it and when, sent by your client unless you turn off Report which skills you use (Install page). Never your code, prompts or file paths.
Shared lessonsOnly if you turn on Help improve skills with what my agent learns (off by default): each confirmed rule your agent chose to share, one sentence, after your client has removed project names, file paths, email addresses and anything that looks like a secret. It is linked to your account so each account is counted once; administrators see counts, not who sent what.
SecuritySign-in attempts (to throttle guessing); for each session its IP address and browser; and a log of sign-ins, security changes, administrator and account actions.

SkilVault does not receive your code, your prompts or your agent's sessions. Skills run on your machine, and the client matches your prompts against your library on your machine too.

How long data is kept

DataKept for
Usage records (including search text and skill uses)90 days, then deleted
Sign-in attempt recordsAbout 1 day
Audit log of account and admin actions180 days
SessionsUntil they expire (30 days, 12 hours for administrators) or you sign out
Account dataUntil you ask for deletion

You can ask the operator to export or delete your data at any time. See Legal for the terms and privacy policy.

Reporting a problem

If you believe a key has leaked, revoke it right away (API keys). To report a security issue or a problem with a skill, contact the operator of your SkilVault deployment.