Account → Personal Vault
Personal Vault shows two cards in one panel:
- Credential Templates holds your saved credentials for templates for interactive connections.
- Personal/Team Credentials holds independent credentials for yourself or selected teams. You can select a compatible entry when a resource connection asks for credentials. This does not save a credential for the template or change credentials used by automation or MCP actions.
Personal/Team Credentials
Create an entry
- Click Create Credential.
- Enter a name, an optional description, and a credential type.
- Choose Personal or Team visibility. For Team, select at least one role.
- Fill the credential fields, then click Save.
Secret fields stay masked when you edit an existing entry. Leaving an existing secret unchanged preserves its value.
Generate a password
Password and passphrase fields offer Generate. In the dialog, choose a length (8–128 characters) and minimum numbers of uppercase letters, lowercase letters, digits and special characters (-_.). Use the up/down arrows or enter numbers directly. The length must accommodate all minimum counts. Set a minimum to 0 if there is no requirement for that type; remaining characters may use any type. Click Generate to fill the field and close the dialog, or Cancel to keep the existing value. Keys and tokens must be supplied separately.
Sharing and ownership
Personal entries belong only to you. Team entries belong to the selected roles, with no individual owner. A current member of any selected role can read, edit, delete or change sharing. General administrator permissions do not grant additional access. Only your current roles are offered for new sharing; previously assigned roles remain visible and are preserved unless you remove them. Team entries require at least one role.
Changing Personal → Team shares the current credential and all historical values. Changing Team → Personal makes the connected user the sole owner and removes everyone else’s access, including access to history. Any current member of a selected team role can make this change.
View, copy and history
Click the eye icon to open a credential. Values are masked until you choose Reveal values or a field’s Copy button. Copy places the selected field’s exact value on your clipboard. Hide values masks them again. Select a version in the paginated history to inspect an earlier value; historical versions are read only and cannot be restored. Every successful save adds a version of the credential values, even if you only changed the name, description or sharing. All versions are retained until the entry is deleted.
The Age column shows the elapsed time since Last Updated (for example, 2d 3h 15m). Editing metadata or sharing also resets this age; it does not necessarily mean the password changed.
Current permissions apply to the complete history. Closing the dialog, selecting another version or leaving the section clears revealed values from the view. Your operating system’s clipboard remains under your control after copying.
Changes from an outdated editor are rejected to protect a more recent save. Close and reopen the entry to load its latest version before editing again.
Deletion, audit and encryption
Deleting an entry permanently deletes all its historical values. Deleting an account removes that account’s personal entries, while team entries remain. A role referenced by a team credential cannot be deleted until its vault references are removed.
Successful entry detail reads, history reads, reveals, saves, sharing changes and deletions create security audit evidence. Audit records contain identities and metadata, never credential values, and remain subject to the security-log retention policy after an entry is deleted.
Current and historical values use MisterShell’s existing server-managed encryption. The server decrypts values for authorized operations; this is not end-to-end encryption or a separate user-held encryption key. Normal server access controls, backups and encryption-key protection remain part of the trust model.
Credential Templates
When a service account credential has Require user credential for interactive sessions enabled (shown by the Template badge in Configuration → Service account credentials), interactive connections use your personal credentials. Save your credential on this page to use it automatically, or leave it Not saved and enter credentials or choose a compatible vault entry when you connect.
Your saved credentials for templates affect your interactive connections. Automation (health checks, snapshots, scheduled jobs) and MCP device actions continue using the service account credential.
What you can do
- See the service account templates that require your own credential.
- Save your own credential for a template.
- Edit or clear a previously saved credential.
Table columns
| Column | Notes |
|---|---|
| Name | The name of the service account credential template. |
| Type | The credential type (Username / Password, SSH Key, AWS Credentials, …). |
| Description | Workspace description for the template. |
| Status | Saved (green) if you have saved your credential (authentication is not verified), Not saved (yellow) otherwise. |
| Age | Time since your saved credentials were last updated; — when not saved. |
| Last Updated | When you last modified your saved credential. |
| Actions | Edit / Clear buttons. |
Common tasks
Save your credential for a template
- Click the pencil icon on the row to save or edit your credential.
- A modal opens with the fields required by the template’s type — for example:
- Username / Password — username, password (plus optional enable password and domain).
- SSH Key — username, private key (and optional passphrase).
- AWS Credentials — access key ID, secret access key.
- Enter your personal values. Secret fields are masked and stored encrypted.
- Click Save.
The status changes to Saved. New interactive connections against resources using this template automatically use your saved credential. (The modal is titled Save your credential the first time and Edit your saved credential on later visits.)
Edit your saved credential
- Click the pencil icon.
- Update any field. Leave secret fields blank to keep the stored value.
- Click Update.
Clear your saved credential
- Click the red trash icon.
- Confirm. Your saved personal credential is erased. The next new connection that needs authentication asks you to enter credentials or select a vault entry; you can also save another credential here.
Provide credentials when connecting
When a template requires personal credentials and you have no saved credential, opening a new connection shows Authentication required:
- Keep Enter manually to enter the complete credential, or choose Use vault.
- With Use vault, search for a credential and select it. Results show its name, type, Personal/Team visibility and description. More results load as you scroll.
- Click Connect, or Transfer for a file transfer. Cancel leaves without starting the operation.
Vault choices include only entries you can access that are compatible with the target resource and connection mode. They can have a different type from the template. For example, a compatible SSH key can be selected even when the template asks for a username and password; RDP only offers types supported by RDP. If no compatible entry is available, use manual entry or create one in Personal Vault.
The connection uses the vault entry’s latest saved value without revealing it in the browser. A vault selection does not save a credential for the template. For supported live connections, Remember this credential saves a manual entry after authentication succeeds; leave it unchecked to connect without saving. Web connections do not offer this automatic saving. Choosing a vault entry records security audit evidence without credential values. If it has become unavailable or incompatible, retry with another entry or enter credentials manually.
Manual entry and vault selection are available for SSH, supported cloud, Kubernetes and database shells, RDP, VNC, web sessions and file browsing. A reusable terminal or file session does not ask again. A fresh graphical or web session can require another prompt. Each file transfer batch opens a separate connection and can ask again, even while the file browser is connected.
For supported live connections, explicit authentication failures reopen the prompt. If your saved credential fails, Update saved credential is checked and read-only: submitting updates your saved credential before reconnecting. Web connections do not support this automatic correction. File browsing and transfers have their own prompts; the live-session remember/correction flow does not apply universally. You can always edit or clear your saved credential in Personal Vault. Selecting a vault entry does not replace an existing saved template credential.
Manual entry supports tokens and OTP values accepted up front by the template’s credential type, such as an AWS session token. It does not add device-driven, multi-round challenge/response authentication. Connection permissions, trust checks and policies still apply to either choice.
Service account credentials and vault entries
Service account credentials (under Manage → Configuration → Service account credentials) are assigned to resources and used by automation. Enabling Require user credential for interactive sessions asks each operator to provide credentials through a saved credential for the template, manual entry or a vault selection. A team vault entry can supply the same remote login to several operators. Session records and audit logs identify the MisterShell operator; attribution on the target depends on the login used for that connection.
Permissions
Every signed-in user manages their own saved template credentials and personal entries. Team entry access follows current membership in one of its selected roles; service account credential permissions do not override vault ownership.