Adding a key without pasting it into the chat
This is the flow that matters. You tell your agent “set up the deploy script
with my personal fal key”. It calls hush_provision, finds no set that holds
one yet, and calls hush_add_secret. A secure input box opens on your
screen:
┌─ hush — add a secret ──────────────────────────┐│ needed to authenticate the deploy script ││ ││ Service: fal.ai ││ Set: personal-fal ││ ││ Paste the value for FAL_KEY: ││ [••••••••••••••••••••••••] ││ [Cancel] [Save] │└────────────────────────────────────────────────┘You paste it there. It is encrypted straight into the vault. The agent gets back
Stored FAL_KEY in "personal-fal" (this project). The value never entered this conversation.
The key went from your keyboard to the vault. It was never in a prompt, never in a transcript, never in a provider log.