Secret Blocks
Secret blocks let you store encrypted values — passwords, API keys, tokens — inline within your markdown notes. They’re encrypted individually with AES-256-GCM and stored as ciphertext in the .md file.
Syntax
Section titled “Syntax”Secret blocks use a fenced syntax with the :::secret directive:
:::secret[Label]your-secret-value:::On save, the plaintext value is encrypted and replaced with the ciphertext:
:::secret[Database Password]enc:v1:aGVsbG8gd29ybGQ...:::Creating Secrets
Section titled “Creating Secrets”Using Templates (Recommended)
Section titled “Using Templates (Recommended)”Press Cmd+Shift+S / Ctrl+Shift+S to open the secret template picker. Available templates:
| Template | Fields |
|---|---|
| Password | Label, value |
| API Key | Label, key |
| Credit Card | Number, expiry, CVV, name |
| SSH Key | Label, private key |
| Env Variable | Variable name, value |
| License Key | Label, key |
| Recovery Code | Label, codes |
| Custom | Label, value |
Manual Syntax
Section titled “Manual Syntax”You can type the :::secret fence directly in the editor:
:::secret[My API Key]sk-abc123def456:::Viewing and Copying
Section titled “Viewing and Copying”- Click a locked secret card to reveal its value.
- Click “Copy” to copy the value to your clipboard (auto-cleared after 30 seconds).
- Secrets auto-hide after 30 seconds of being revealed.
- Click again or press Escape to re-lock immediately.
Convert Selection to Secret
Section titled “Convert Selection to Secret”Already have credentials pasted in a note? Select the text, right-click, and choose Convert to Secret(s).
Claspt detects key-value pairs from common formats:
| Format | Example |
|---|---|
| Key: Value lines | Username: alice |
| Markdown tables | ` |
| ASCII tables | Username alice |
| Environment variables | API_KEY=sk-abc123 |
| Email / password pairs | alice@example.com / hunter2 |
You can choose between:
- One Secret — all credentials combined into a single encrypted block
- Separate Secrets — one encrypted block per credential
A preview lets you uncheck items you don’t want to encrypt. Labels are auto-suggested from nearby headings.
Security Details
Section titled “Security Details”- Each secret block is encrypted with a unique nonce (AES-256-GCM).
- Secret values are encrypted — labels remain plaintext for searchability.
- The encryption key is derived from your master password via Argon2id.
- Key material is wiped when the vault locks; decrypted values are collapsed but not scrubbed from memory (see Security Model).
- Secret values are never indexed by the search engine — only labels are searchable.
Templates
Section titled “Templates”Cmd+Shift+S (Ctrl+Shift+S) opens the template picker: thirteen built-in
templates (login, API key, SSH key, card, bank account, licence key, database,
Wi-Fi, identity document and more) plus any you add under Settings ›
Automation › Templates. The same list is in the browser extension’s Add
new form, and the Help pages list every template and its fields.
Two-factor codes
Section titled “Two-factor codes”A login can hold its two-factor key. Add it to the block (paste the
otpauth:// key, or let the browser extension read a site’s QR code) and the
live six-digit code shows beside the password, on the desktop, in the
extension and on the phone. Keeping both factors in one vault is convenient
and a weaker separation than a separate device; it is your choice.
Rotation reminders and the audit
Section titled “Rotation reminders and the audit”- Settings › Automation › Password rotation reminder lists passwords older than a limit you set. Because the generator records when it made a password, the age is real; for a password typed by hand it is the page’s last save.
claspt auditon the command line, or the Utilities tab, lists every place a secret sits in the vault unencrypted, by page and label, never by value.