Private beta: the source and binaries are not public yet, so the install commands do not work yet.
aisync

Using Vault

If you already run HashiCorp Vault, keep tokens there and only references in your setup.

When to use it

The default (a secrets.json encrypted with your passphrase) needs no server. If you already run Vault, keeping tokens in Vault KV v2 is better:

Set up

aisync vault login --addr https://vault.example.com

Asks for a Vault token, checks it and stores it in the keychain. VAULT_TOKEN is used if set. The token needs read access to the paths you use, and write access if capture should move tokens there.

Move tokens to Vault on capture

aisync capture default --vault claude/aisync

Tokens found in MCP servers go to claude/aisync/<server>-<key> (KV v2 mount claude) in the value field, and the setup keeps a reference:

"SLACK_BOT_TOKEN": "{{vault:claude/aisync/slack-slack_bot_token#value}}"

You can write references by hand as {{vault:<mount>/<path>#<field>}}; the field defaults to value.

On other machines

aisync vault login --addr https://vault.example.com
aisync pull default

A machine not logged in to Vault stops at pull and says what's missing. After the pull, aisync reads the value from Vault every time Claude Code starts the server.

Verified behaviour

Checked against a real Vault (1.18):

Any Vault works, within these limits

You choose the server with --addr, so a Vault you run yourself works. This version requires:

Item Supported
Secrets engine KV v2 only. KV v1 mounts can't be read
Login Vault tokens only. No OIDC, AppRole or userpass login yet
Token expiry aisync doesn't renew tokens. An expired token stops MCP servers from starting, so use a periodic token and run vault login again when needed
Certificates Ones your system trusts. A self-signed CA can't be configured
Enterprise namespaces Not supported
Servers One Vault address per machine

Give the token a policy that allows only the paths it needs. A root token in your setup opens all of Vault if that machine is compromised.

These docs describe aisync 0.1.