Secrets exist but are never observable.
v1.4.0 — Production Ready
Your AI coding assistant can read your .env files. Every API key, every database password — visible, loggable, leakable. Phantom Vault makes it so your AI can use your secrets without ever seeing them.
Run phantom init and set a master password.
Run phantom add openai-key — paste your key when prompted.
Run phantom mcp-install — restarts Claude automatically.
Tell Claude: "Use my openai-key to check my API balance"
Master key lives in Apple Secure Enclave or TPM. No password file exists anywhere.
Commands are analyzed before execution. Character-by-character probing is blocked.
Output scanned for secrets in 15+ encodings. Base64, hex, URL-encoded — all caught.
Commands run in network-restricted subprocesses. Secrets die when the process dies.
Honeypot secrets detect exfiltration attempts. Get alerted the moment something probes.
One command to connect. Your AI agent gets 6 tools — none return plaintext secrets.