Skip to content

Secret Blocks

Secret blocks let you store encrypted values — passwords, API keys, tokens — inline within your markdown notes. They’re encrypted individually with AES-256-GCM and stored as ciphertext in the .md file.

Secret blocks use a fenced syntax with the :::secret directive:

:::secret[Label]
your-secret-value
:::

On save, the plaintext value is encrypted and replaced with the ciphertext:

:::secret[Database Password]
enc:v1:aGVsbG8gd29ybGQ...
:::

Press Cmd+Shift+S / Ctrl+Shift+S to open the secret template picker. Available templates:

TemplateFields
PasswordLabel, value
API KeyLabel, key
Credit CardNumber, expiry, CVV, name
SSH KeyLabel, private key
Env VariableVariable name, value
License KeyLabel, key
Recovery CodeLabel, codes
CustomLabel, value

You can type the :::secret fence directly in the editor:

:::secret[My API Key]
sk-abc123def456
:::
  • Click a locked secret card to reveal its value.
  • Click “Copy” to copy the value to your clipboard (auto-cleared after 30 seconds).
  • Secrets auto-hide after 30 seconds of being revealed.
  • Click again or press Escape to re-lock immediately.

Already have credentials pasted in a note? Select the text, right-click, and choose Convert to Secret(s).

Claspt detects key-value pairs from common formats:

FormatExample
Key: Value linesUsername: alice
Markdown tables`
ASCII tablesUsername alice
Environment variablesAPI_KEY=sk-abc123
Email / password pairsalice@example.com / hunter2

You can choose between:

  • One Secret — all credentials combined into a single encrypted block
  • Separate Secrets — one encrypted block per credential

A preview lets you uncheck items you don’t want to encrypt. Labels are auto-suggested from nearby headings.

  • Each secret block is encrypted with a unique nonce (AES-256-GCM).
  • Secret values are encrypted — labels remain plaintext for searchability.
  • The encryption key is derived from your master password via Argon2id.
  • Key material is wiped when the vault locks; decrypted values are collapsed but not scrubbed from memory (see Security Model).
  • Secret values are never indexed by the search engine — only labels are searchable.

Cmd+Shift+S (Ctrl+Shift+S) opens the template picker: thirteen built-in templates (login, API key, SSH key, card, bank account, licence key, database, Wi-Fi, identity document and more) plus any you add under Settings › Automation › Templates. The same list is in the browser extension’s Add new form, and the Help pages list every template and its fields.

A login can hold its two-factor key. Add it to the block (paste the otpauth:// key, or let the browser extension read a site’s QR code) and the live six-digit code shows beside the password, on the desktop, in the extension and on the phone. Keeping both factors in one vault is convenient and a weaker separation than a separate device; it is your choice.

  • Settings › Automation › Password rotation reminder lists passwords older than a limit you set. Because the generator records when it made a password, the age is real; for a password typed by hand it is the page’s last save.
  • claspt audit on the command line, or the Utilities tab, lists every place a secret sits in the vault unencrypted, by page and label, never by value.