supabase-vault
Installation
SKILL.md
Supabase Vault — Enhanced Secret Storage
Replaces the local secrets.json vault with Supabase Vault. All OpenClaw API keys, tokens, and auth credentials are stored AES-256 encrypted in your Supabase Postgres database. Bootstrap credentials (the Supabase URL + service_role key needed to reach the vault) are encrypted locally using OS keychain or machine-derived AES-256-GCM.
See references/architecture.md for the full threat model and design rationale.
Prerequisites
- A Supabase project (free tier works). Get one at supabase.com.
- Project URL + service_role key (from Supabase Dashboard → Settings → API).
- Node.js 18+ (already available in OpenClaw's environment).
Installation
Step 1 — Install @supabase/supabase-js
npm install --prefix ~/.openclaw/skills/supabase-vault @supabase/supabase-js