Security
We can't read your secrets.Or your personal files.
They're encrypted on your devices, with a key only your devices hold; the server keeps ciphertext. Here's exactly what it can read, and why.
What the server can't readsealed on your devices
Your secrets and personal files are encrypted on your devices, with a key only your devices hold. The server keeps the ciphertext and checks its shape. That's all it can do with it.
Secrets in your vault
Encrypted with AES-256-GCM on your machine. The server keeps the ciphertext, plus the names so it can list them. Each value is bound to its name, scope and environment, so it can't be swapped for another.
Personal files
Notes and local files outside git are sealed with the same vault key, with versions. The server sees their paths and sizes, not what's in them.
History, end to end
With 0b history mode e2e, conversations are sealed with your vault key too. The server keeps ciphertext and the tool, repo and dates; only your devices can search it.
A new machine gets the key from you
It comes from a machine you already have, through a key exchange the server relays but can't read. Both screens show a code, so a swapped key would be caught.
The dashboard opens values in your browser
Your passkey unlocks the vault key in the browser, so values are decrypted on your screen, not on the server. A recovery key you keep covers losing every device.
What the server can readand why it has to
Some things the server has to read to do its job. Each one is kept to what that job needs.
Your service logins
The OAuth tokens and API keys of the services you connect. To call Linear for you, the server has to use your Linear login.
They're encrypted at rest with a key per user (AES-256-GCM) and used only to make the calls your tools ask for. Disconnecting a service deletes them.
Conversation history, if you turn it on
Off until you run 0b history on. By default the text is stored readable, so your coding agents can search it through 0bridge; your vault's values and text shaped like keys are masked on your machine before upload.
Want it sealed instead? 0b history mode e2e encrypts it with your vault key, and search runs on your devices.
Clipboard items
What you send with 0b clip, until an agent reads it or 10 minutes pass. Reading an item removes it.
The audit log
Sign-ins, changes to connections, tokens and secrets, and for each tool call: which tool, whether it worked, how long it took and when (with a short error message if it failed).
Never what was sent or what came back. Rows are deleted after 90 days; encrypted backups can hold them up to 12 weeks longer.
Your agents use secretswithout being handed the values
Commands get secrets by name. What your agent reads back is masked, and production waits for you.
- Use them by name
0b exechands a command its secrets as environment variables. No.envfile on disk. - Masked in outputIf a value shows up in what the command prints, your agent reads
***. - Production needs youProduction values reach a machine only after you approve it in your browser, with your passkey (or a new email code if you have none), for 30 minutes, 2 hours or 8 hours.
- The honest limitAn agent that deliberately prints its environment can still see values. Masking stops accidents; the approval is what guards production.
Signing inand every device you've signed in on
Your account is the key to your logins, so the steps that hand out access ask you to prove it's you again.
Email code, Google or GitHub
Add a passkey under Settings for the strongest sign-in. Ten recovery codes, each used once, cover a lost passkey.
Re-confirm what matters
Approving a new device, giving an app access and creating a token need a sign-in from the last 10 minutes, with your passkey if you have one.
A token per device
The server stores only a hash of each device's token. Signing out revokes it, and Settings → Devices revokes any of them.
claude.ai and ChatGPTget your tools, not your vault
Chat apps connect as custom connectors, with a consent screen you approve. Setting them up
OAuth 2.1 with PKCE
The consent screen shows the app and where it sends you back to. Its access tokens only work for your endpoint and expire within an hour.
Can't change your vault
Apps connected this way can call your tools. They can't add, change or delete secrets, and can't add API keys.
No conversation history
claude.ai and ChatGPT don't get the history tools, so your coding sessions stay with your coding agents.
Source availableand honest about what's next
You shouldn't have to take our word for the parts that hold your key.
Read the client
We're publishing the 0b CLI and the core library it shares with the dashboard, including the code that encrypts your vault, as source available under the Functional Source License (FSL-1.1-ALv2). Each version becomes Apache 2.0 two years after its release.
What we're still working on
- A device's token can do most of what your account can, short of creating tokens or using production values without you. Narrower tokens are planned; a project's token already opens only that project.
- Revoking claude.ai's or ChatGPT's access from the dashboard isn't there yet; remove it in the app.
- Tool descriptions from services you connect reach your agent as those services wrote them. Treat an unfamiliar MCP server like any code you'd run.
Found a problem?Tell us first.
Write to support@0bridge.dev with "Security" in the subject. Security reports get an answer first. Please don't post them publicly before we've replied.