Overview
PentaVault is a security-first control plane for runtime secrets, project access, proxy tokens and audit visibility. It is built for AI-assisted development, where the goal is to give tools and agents the secrets they need at runtime while limiting how often plaintext secrets are exposed on developer machines.
Architecture
- ClientsNext.js dashboard · Rust pv CLI
- APIFastify · Better Auth
- StoragePostgreSQL · Drizzle
A Next.js 16 dashboard and a Rust CLI talk to a Fastify API that handles authentication, encrypted secret storage, project access policies and runtime resolution, with PostgreSQL behind it.
Security model
- Secrets are stored encrypted, and access is deny-by-default per project.
- Every access is written to an audit log.
- The CLI signs in with a device-code flow (
pv login) and is read-only: list projects, environments and secrets, pull them, orpv runa process with secrets injected at runtime.
Testing
The dashboard runs lint, type checks and unit tests, with browser flows covered by Playwright (UI-only tests run against mock auth). The CLI has its own build, lint and test pipeline.

