…
## Using it
-- **Add** a secret: a name (`github-pat`), the value and a note. After you save it, the value is never shown again, to anyone: the page shows only its last four characters.
+- The tab opens with **Add** on top and then one row per secret: its name, its note and the agents allowed to use it, as chips. Tap a row and its details open underneath it, in place — one at a time.
+- **Add** a secret: a name (`github-pat`), the value and a note. After you save it, the value is never shown again, to anyone: the row shows only its last four characters.
+- **A value can be several lines**, or a small JSON. A service that needs an endpoint, a region, a bucket and a key pair at once is one secret, not five; your agent reads the text back exactly as you pasted it and makes sense of it itself. The last four shown are of the whole text, so that is what you paste again when you allow another token.
- **+ allow** a token: pick one of your AI tokens from the list (grouped by project) and give the value again. d2 checks it's the saved value (by its last four) and seals a copy for that token only. A token that has never been used shows *Waiting for this agent to connect once*: its lock key is made the first time it's used, so pick it after that.
- Your agent reads it with its own token: `GET /api/v2/vault/<name>` (or the MCP tool `vault_get`). Any other token gets `E_SECRET`.
…