Storing a secret is only half the job — eventually someone needs to use it. In StretchVault, seeing a secret is a distinct, controlled action called a reveal. This article explains how reveal works, who can do it, and how to use secrets safely.
Why reveal is a separate action
Across StretchVault, list views, dashboards, search results, and reports show only item metadata — title, username, URL, tags, strength, and exposure. The secret value is deliberately excluded from all of them. The only way to see a secret is to reveal a single item on purpose. This design means a stolen screenshot of your item list never contains a password, and every time a secret is actually exposed, there's a record of it.
How to reveal a secret
- Open StretchVault and find the item, either in the Items tab or inside its vault.
- Open the item to view its details.
- Click Reveal.
- StretchVault decrypts that one secret and displays it so you can read or copy it.
- The reveal is written to the access log with your identity, the item, and the time.
Only the specific item you reveal is decrypted, and only at that moment. Nothing else in the vault is affected.
Who can reveal
Reveal permission is intentionally stricter than viewing metadata:
- Owners and admins of the organization can reveal items in the vaults they administer.
- Everyone else can reveal an item only if they've been given a grant with reveal (or edit) scope for that specific item. A grant with only view scope lets someone see the item's details but not reveal its secret.
If you try to reveal an item you don't have permission for, StretchVault refuses the action with a clear "you do not have permission to reveal this secret" message. To get access, ask an owner, admin, or the item's manager to share it with you at reveal scope (see Sharing Secrets and Managing Access).
A realistic example
At Meridian Studio, account manager Dana needs the client's ad platform login to launch a campaign. The password lives in the Client Credentials vault, which only the owner administers. The owner opens the item, chooses Share, enters Dana's email, sets the scope to reveal, and adds an expiry of two weeks. Dana can now open that one item and reveal the password when she needs it — and when the campaign wraps, the grant expires on its own. The owner can later open the access log and see exactly when Dana revealed it.
Using secrets safely after reveal
- Copy the secret directly into the destination field (the site's password box), then move on — don't paste it into chats, documents, or emails.
- Clear your clipboard after pasting a sensitive value, especially on shared machines.
- Prefer sharing a grant over revealing and forwarding a secret. Forwarding defeats the audit trail; a grant keeps the reveal accountable to the person who actually used it.
- If you reveal a secret on a device you don't fully trust, treat that credential as potentially exposed and rotate it afterward.
Tips
- Reveal only when you're about to use a secret, not to "check" it — every reveal is a logged event.
- If several people keep asking you for the same password, that's a signal to share the item at reveal scope instead of revealing it for them repeatedly.
- Combine reveal discipline with 2FA on the underlying account so that even a leaked password isn't enough on its own.
Troubleshooting
"You do not have permission to reveal this secret." You aren't an owner/admin for that vault and don't hold a reveal-scope grant. Ask for the item to be shared with you at reveal scope.
"This item has no stored secret." The item was saved without a secret value (metadata only). Edit the item and add the secret, then reveal.
"StretchVault encryption is not configured." The system can't decrypt because the master encryption key isn't available. Check the Health tab and contact your administrator — this affects the whole workspace, not just your item.
FAQ
Does revealing change the secret? No. Reveal only decrypts and displays the existing value; it doesn't alter or rotate it.
Can I see who has revealed an item? Owners and admins can review the access log, which records every reveal along with who and when.
Was this helpful?
Help us improve this article
Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.

