Skip to main content
An external-vault connection lets Darwin resolve an opaque item reference during authorized execution. The secret remains controlled by the external vault and is not imported into Darwin Vault.

Resolve just in time

Darwin stores connection metadata and the item reference needed for future resolution. Secret values are excluded from model context, Action results, logs, traces, analytics, and webhooks.

Prefer a provider-specific adapter

Use the dedicated 1Password or Dashlane guide when possible. Other password managers must provide a documented, scoped machine-access mechanism. A browser extension, copied export, screen scrape, or user master password is not an acceptable integration boundary. The user can revoke the external-vault connection without deleting prior content-free Action receipts. Copying a secret into Darwin Vault is a separate, explicit migration—not a side effect of resolution.
Last modified on September 22, 2026