Why this site exists.
Teams need a practical way to discuss what happens to provider keys when applications use them. This site proposes a shared vocabulary: keep the original key outside the caller, mediate and constrain access, observe activity safely, and make access revocable.
We want the definition to be useful in architecture discussions and product evaluations. The principles are written as questions that can be tested against an implementation.
How to use the guide.
Start with the definition, follow the request path, and then use the principles to examine a real system. The comparison page explains how the approach relates to other security controls.
The definitions and evaluation questions are an explanatory framework. They do not establish a formal certification or independently recognized industry standard. Product examples illustrate specific implementations and their documented limits.
How we approach the content.
Define the boundary.
Explain where a provider key exists, who can use it, and what happens when access is withdrawn. Describe both the intended protection and its limits.
Distinguish the claims.
Separate proposed category criteria from documented product behavior. A principle should not be mistaken for an implemented feature.
Acknowledge related work.
Reference existing secrets-management, brokered-access, and workload-identity practices. Describe overlap fairly.
Keep evidence visible.
Link to primary documentation. Avoid invented customer stories, performance figures, certifications, or claims of exclusive invention.
Sources and further reading.
These primary sources provide context for the architectural concepts and implementation example described on this site.
- OWASP Secrets Management Cheat SheetSecret lifecycle, access control, auditing, rotation, and runtime handling.
- GitHub: About secret scanningFinding supported secrets exposed in repository content.
- CyberArk: How Secretless worksBrokered service access that keeps target credentials outside the client.
- Introducing Secretless Broker, 2018Historical context for established credential-brokering techniques.
- SPIFFE overviewIdentity for workloads and associated authentication concepts.
- VaultProof security modelProduct-specific handling of provider credentials, request metadata, and trust boundaries.
- VaultProof documentationSetup and supported application integration patterns.
Editorial date: September 5, 2026. Product documentation can change; consult current implementation details when evaluating a system. Listing a source does not imply its endorsement of this guide.
Site privacy.
This version of the site has no account system, forms, advertising trackers, or analytics scripts. Reading the guide does not require submitting an API key or other credential.
The hosting provider may process ordinary connection information needed to serve pages. Links to other websites take you to services with their own policies.