Committed by accident
API keys slip into history. Scrubbing git doesn't revoke what already leaked to GitHub, Slack, or a contractor's laptop.
For teams shipping on Stripe + Render
Akita Vault gives you one command to vault env files, sync Stripe and Render, run the first rotation, and keep keys fresh on a monthly GitHub schedule — so you ship instead of firefighting leaks.
£25/org/year introductory · £49/yr standard from second renewal · one license, unlimited repos · vault-init --yes per project
The problem
Most teams know they should rotate keys and keep .env out of git — but the playbook lives in someone's head, a Notion doc, or a one-off script that nobody trusts on a live app.
API keys slip into history. Scrubbing git doesn't revoke what already leaked to GitHub, Slack, or a contractor's laptop.
.env.local, .env.production, Render dashboard, CI secrets — no single source of truth, easy to drift.
Stripe webhooks, AUTH_SECRET, admin tokens — each rotation is manual, scary, and postponed until after the incident.
The solution
A Cursor plugin + CLI workflow built for real stacks: bootstrap a gitignored vault/, symlink env for local dev, pull production from Render, rotate internal secrets and webhooks, and prove the automation bundle wasn't altered before it touches your APIs.
cpk_live_ keys + online attestation APIHow it works
Copy the plugin, set AKITA_VAULT_LICENSE from checkout email, reload Cursor.
@vault-director or vault-init --yes from your repo root — migrates, connects, rotates, schedules.
GitHub rotates monthly; pull fresh Render env locally with npm run vault:pull-render after CI.
What you get
Gitignored vault/, tracked .vault/config.json, symlinks for Prisma and Next.js — same pattern every repo.
Webhook recreation, internal token rotation, Render env push + deploy — uses your CLI keys, not the wrong Stripe MCP account.
Workflow with AKITA_VAULT_LICENSE — rotation fails closed without a valid license.
Signed SECURITY/MANIFEST.json — tampered scripts never reach your providers.
Skills, rules, @vault-director agent, slash commands — fits how your team already ships.
Vault stores & rotates; Akita Clear scans source and strips literals before merge — complementary, not duplicate.
Honest comparison
Enterprise secret platforms — HashiCorp Vault, AWS Secrets Manager, Doppler, 1Password Secrets Automation, Infisical Cloud — are built for centralized runtime secret injection, audit at scale, and platform teams. They are powerful. They are also expensive, slow to adopt, and overkill when your real problem is “.env files in git and nobody rotates the Stripe webhook.”
HashiCorp · AWS · Doppler · 1Password · Infisical…
£25 intro · £49/yr standard · unlimited repos
vault/ per repo on your machine + provider dashboardsvault-init --yes from Cursor or CLIIllustrative ranges for small teams — enterprise tiers and usage-based billing climb faster. Akita stays flat per org.
You need dynamic database credentials, HSM-backed keys, org-wide audit exports, or every microservice pulling secrets at runtime from one control plane.
You ship on Render/Stripe (or similar), secrets live in .env files and dashboards, and you want them out of git, synced, and rotated on a calendar — without hiring a platform team.
Akita platform
| Akita Vault £25 intro | Akita Clear Free | |
|---|---|---|
| Primary job | Store secrets, sync providers, rotate on schedule | Scan source, move keys to env, strip literals |
| Best for | Live apps on Render/Stripe with real env sprawl | Every repo before merge — dev & CI hygiene |
| Automation | Monthly GitHub Actions + one-command init | akita clear / @akita-secret-clear |
| Pricing | £25/org/year intro · £49/yr standard · unlimited repos, one license | Free (limited-time org offer) |
| Get started | Subscribe | GitHub sign-in |
Pricing
£25/year introductory is not per repo. You buy one subscription per organization (one cpk_live_ license key). Standard renewal is £49/org/year. Run vault-init on as many repos as you need — each project gets its own gitignored vault/ folder and optional GitHub rotation workflow.
One checkout · one license key · all devs on the same org can use it
Each repo = its own vault/ + .vault/config.json — not a shared cloud vault
Agency with multiple clients? One subscription per client org (separate license keys)
Akita Vault · launch offer
£25/org/year
Introductory first year · £49/yr standard from second renewal
One org license — use on every repo your team ships. Full init, rotation, GitHub schedule, signed releases.
vault/ + rotation workflowcpk_live_ + online attestation APILaunch pricing applied at checkout · license key emailed after Stripe
Akita Clear
Free
CLI + Cursor plugin for scan, explain, move & clear — limited-time org offer.
akita clear full pipelineQ&A
Pricing, scope, and how Vault fits your stack.
Many projects, one price. £25/year introductory buys one organizational license — not one repo.
Standard renewal is £49/org/year. You receive a single cpk_live_ key (emailed after checkout). Use that same key on every repository in your org:
run vault-init --yes (or @vault-director) from each project root.
Each repo gets its own gitignored vault/ folder and .vault/config.json —
think “one license, many local vaults,” not one shared vault in the cloud.
You do not pay £25 again per app unless you need a separate organization (e.g. a different client or company).
Those are centralized secret platforms — hosted stores or clusters your apps call at runtime, with per-seat or per-secret pricing and platform-team setup.
Akita Vault is a developer workflow: gitignored vault/ folders in your repos, symlinks for local dev, and automated sync/rotation to Stripe + Render.
You are not buying a secret server. You are buying a Cursor plugin + automation that stops env sprawl and makes rotation a scheduled habit — at £25/org/year introductory (£49/yr standard) instead of hundreds or thousands for team SaaS or self-hosted Vault ops. Many teams use both later: Akita to clean up shipping, enterprise vault when compliance demands central runtime injection.
Your subscription renews at the standard £49/org/year rate unless we announce a change in advance.
You keep the same cpk_live_ license key and all repos you have already initialized — no per-repo fees.
Cancel anytime from the Stripe customer portal linked in your receipt email.
Akita Vault only (£25 intro / £49/yr standard) — secrets workflow + rotation for teams on Stripe + Render.
Enterprise Delivery Stack (£299 intro / £499/yr standard) — all paid CPK plugins, the same cpk_live_ Vault license, install-stack.mjs, and onboarding call. Brand DNA is a separate platform add-on when you are ready.
Buy Vault on plugins or the full stack on enterprise.
The organization tied to your purchase — typically your company domain on the Stripe checkout email
(e.g. everyone at @acme.com shipping repos under Acme).
One license key per checkout. Consultancies billing multiple clients should purchase one subscription per client org.
Set AKITA_VAULT_LICENSE in your environment, store the key in each repo’s .akita/licenses.json,
or add AKITA_VAULT_LICENSE as a GitHub Actions secret per repository that runs monthly rotation.
The license API validates the same key across projects — no per-repo fee.
Bootstrap is dry-run first. Real env files are backed up to .vault/backups/ before migration. Rotation always previews before apply.
sk_live rotation?Vault rotates webhooks and internal tokens automatically. Full API key rotation still uses Stripe's 7-day grace in the Dashboard — we document the exact steps in your vault runbook.
Recommended: Clear before every merge (source hygiene), Vault for storage, provider sync, and scheduled rotation on deployed apps. Clear is free; Vault is the paid automation layer.
Ed25519-signed release manifest verified before init/rotate. Paid features require cpk_live_ validation against our license API.
Vault is £25/org/year introductory today (£49/yr standard from second renewal). Team seats and hosted rotation are on the roadmap — contact hello@cursorpluginkits.com if you need multi-org billing or SSO.
akita clear — scan, explain, move keys to env, strip literals, verify. No credit card.
One command does it all — scan, explain, move keys to env, strip literals, verify.
akita clear — full pipelineakita clear --dry-run — preview firstInvoke the same pipeline from chat — rules and hooks keep CI and IDE in sync.
@akita-secret-clear → akita clearakita-secrets.mdc rulesAkita Clear — one command
Subscribe to Akita Vault for automation, or start free with Akita Clear and upgrade when you're ready to rotate on schedule.