Vault as an access boundary
Folders and CLI toggles are the main safety controls.
Import from files in the app
On macOS, open Vault → New Item dropdown → Import from Files and choose Scan for Secrets or Adopt SSH Keys. The source starts at ~/.zshrc for secrets or ~/.ssh for SSH keys, so you can preview immediately. Edit the path or use Browse to choose another source; Use Default restores the suggested path. Choose a destination folder, preview the proposed changes, select items, choose Password or API Key for each ordinary credential, then confirm Save and Apply Changes. The reference preview updates to match the chosen category. Shell expressions and computed values are skipped. Preview does not write to the vault or source files. Replace originals after saving is checked by default. Clear it to save only, leaving source files, SSH config, and shell integration unchanged. Replacement supports literal exported assignments in custom shell files such as ~/.gamesx-env, writing quoted authsia:// object URIs without command substitution. Matching CLI-enabled passwords and API keys can be reused on retry. For an existing password, API key, or SSH key in the destination folder, select Overwrite existing value to replace its saved value; this is off by default. The overwrite choice is tied to the reviewed item and included in the single approval. Only one source can be selected to overwrite each existing item. Ambiguous matches and items with CLI access disabled are skipped. Environment-tagged items never count as conflicts. Item IDs, other metadata, and SSH access restrictions are preserved. Imports retain only the latest source-file backup per machine, removing older copies (including a Workspace setup original) after the new snapshot is stored. One vault approval covers the selected items, required backups, and SSH storage verification. Newly scanned secrets and adopted SSH keys have CLI access enabled by default. Conflicts without an overwrite choice are skipped. Scrape backs up and rewrites supported environment and shell files; SSH adoption verifies vault storage before replacing local private keys with Authsia stubs. Changed source files require a new preview.
Prefer references
Put authsia:// refs in scripts and env files. Secrets resolve only at approved runtime.
SSH via the agent
Git and SSH should sign through Authsia’s agent — not by exporting private keys into the shell. See Secure SSH & Git.
Copy Path stays shell-ready
Copy Path yields export NAME='authsia://…' so pasted refs stay visible to child commands.