# Vault + passphrase The vault is IndexedDB database **`tabbot-vault`** on **this origin only**. ## Cryptography - Secrets (bot tokens, named secrets): **AES-256-GCM** via Web Crypto - Unlock key: **PBKDF2-SHA-256**, **600,000** iterations, random salt in vault metadata - Unlocking keeps a master key in memory. **Lock** drops it. There is no HoneyPeer KMS. If you forget the passphrase and did not export a backup, the ciphertext is gone. ## Remember this browser profile Opt-in. Stores a wrapped master key so this profile can unlock without typing. Convenient on a machine you own. **Dangerous on a library PC, sibling laptop, or shared profile.** Prefer a dedicated browser profile for TabBot. ## Reveal, copy, export, wipe - Reveal requires unlock. Copy uses the Clipboard API and TabBot tries to clear it after 30 seconds when the browser allows. - **Export** is encrypted JSON (`tabbot-vault.backup.json`). It is not a plaintext token dump. Import replaces vault contents — treat it like restore. - **Wipe vault** deletes this origin’s database. Discord applications remain in the Developer Portal until you delete them there. ## Named secrets API keys are **not** project JSON. Studio → **Settings → Named secrets** stores `namespace/name` values (for example `llm/apiKey`, `translation/apiKey`) in the same AES-GCM store. Module fields typed as `secret()` write that vault. The runner handshake carries a bag; Code uses `vault.revealSecret(namespace, name)`. Full workflow: [Named secrets](/docs/guide/named-secrets). Do not paste those values into Discord, git, or share codes. ## What is stored Encrypted tokens, vault meta, bot projects (IR, TypeScript, module settings), KV variables, named secrets. Logs are not a second copy of the token; if a log ever showed a token, rotate it. See also [Privacy](/legal/privacy), [Security](/legal/security), and [Community](/docs/guide/community).