Skip to content

article

Troubleshooting Common StretchVault Errors

Understand the messages StretchVault shows when a save, reveal, share, or audit can't complete — and how to fix each one.

When StretchVault can't complete an action, it tells you why with a clear message. This guide lists the ones you're most likely to see, what each means, and how to resolve it.

Encryption and secrets

"StretchVault encryption is not configured."

What it means: No master encryption key is available, so StretchVault can't encrypt (or decrypt) secret values. As a fail-safe, it refuses to store secrets rather than save them unprotected.

How to fix it:
1. Open the Health tab and check the encryption status.

2. If it shows disabled, contact your workspace administrator — this is a workspace-level configuration, not something an individual member sets.

3. In the meantime, you can still create items without a secret value (metadata only) and add the secret once encryption is enabled.

"This item has no stored secret."

What it means: You tried to reveal an item that was saved without a secret value.

How to fix it: Edit the item, add the secret in the secret field, save, then reveal.

Permissions

"You do not have permission to reveal this secret."

What it means: You're not an owner/admin for that vault and you don't hold a reveal- or edit-scope grant on the item. A view-scope grant is not enough to reveal.

How to fix it: Ask an owner, admin, or the item's manager to share the item with you at reveal scope. See Reveal Permissions and Roles.

"Authenticated organization is required."

What it means: StretchVault couldn't determine which organization your request belongs to — usually a session that lost its workspace context.

How to fix it: Make sure you've selected your workspace, then reload StretchVault. If it persists, sign out and back in.

Saving items and folders

"An item title is required."

What it means: Every item — even a Secure note — must have a title.

How to fix it: Enter a title and save again.

"A vault is required." / "A vault name is required."

What it means: You tried to save an item without choosing a vault, or create a vault without a name.

How to fix it: Select the destination vault for the item, or enter a name for the new vault, then save.

"Vault not found."

What it means: The vault you referenced doesn't exist in your organization (or you don't have access to it).

How to fix it: Reload the Vaults tab, confirm the vault exists and is yours, and try again. If you followed an old link, the vault may have been deleted.

"A folder name or path is required."

What it means: You tried to create a folder without a path.

How to fix it: Enter a path such as Clients/Acme (leading/trailing slashes are trimmed; max 180 characters) and save.

Sharing

"A valid recipient email is required."

What it means: The email you entered to share with was blank or malformed.

How to fix it: Enter a complete address containing an @, then set the scope and confirm.

"Grant not found."

What it means: You tried to revoke a grant that no longer exists — it may already be revoked or expired.

How to fix it: Refresh the Sharing tab to see the current list of active grants.

Security engine (Watchtower, Breach-watch, rotation, generator)

"StretchVault engine is not enabled."

What it means: The security engine that powers strength analysis, the generator, Watchtower, Breach-watch, and rotation planning is turned off.

How to fix it: Open the Health tab to confirm the engine status and contact your workspace administrator to enable it. Storing and revealing secrets still works without the engine; only the intelligence features are affected.

The security engine seems unreachable or a review times out

What it means: The engine is enabled but StretchVault couldn't reach it for that request.

How to fix it:
1. Wait a moment and retry — transient blips resolve on their own.

2. Check the Health tab; if the engine is reported down, notify your administrator.

3. Note that storing, editing, revealing, and sharing secrets don't depend on the engine, so those keep working while it recovers.

When items look wrong in security reviews

  • An item shows "old" after I rotated it. Age is measured from the last saved secret change. Ensure you saved a new secret value (a blank secret field keeps the old value and its date).
  • An item shows "reused" but looks unique. Reuse is by fingerprint across the vault; the identical value exists on another item. Regenerate one of them.
  • A newly imported item isn't scored. Items saved before analysis was available aren't scored until re-saved. Edit and re-save the secret, or run Watchtower.

Tips

  • The Health tab is your first stop for anything encryption- or engine-related — most "why won't this work" answers are there.
  • Most errors are recoverable in place; you rarely need to re-create an item.
  • If a whole category of features is down (all reveals, or all reviews), it's a workspace-level configuration issue for your administrator, not a per-item problem.

FAQ

Do these errors ever expose my secret? No. Error messages describe what went wrong without ever including the secret value.

Who can fix encryption or engine problems? Your workspace administrator — encryption and the security engine are configured at the workspace level, not per member.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.