Vault
Tested with: Not yet available on Databasezy · describes the launch design
Vault keeps secrets such as API tokens encrypted inside your own database, so SQL, cron jobs and database functions can use them without the plaintext appearing in your schema or backups.
How it works (at launch)
Section titled “How it works (at launch)”- Secrets are stored encrypted with
vault.create_secret(...)and read through thevault.decrypted_secretsview, compatible with Supabase’ssupabase_vault. - The portal lists secrets by name and description, creates, rotates and deletes them; values are write-only there.
- Access to the decrypted view is limited to the roles you grant.
select vault.create_secret('sk_live_...', 'stripe_key', 'Stripe API key for the billing sync');select decrypted_secret from vault.decrypted_secrets where name = 'stripe_key';