Introduction
Introduction to Stashbase as a platform
Stashbase helps teams ship securely with coding agents—from development to production.
It manages application secrets across projects and environments, and adds scoped controls for how developers, services, and coding agents use credentials, APIs, MCP tools, files, commands, and dependencies. Raw secret values stay outside the Agent Proxy boundary.
What Stashbase does
At a high level, Stashbase helps you:
- store and organize application secrets across projects and environments
- give developers, services, and coding agents only the access they need
- keep raw credential values out of agent processes
- run coding agents in a native or Docker sandbox with network and filesystem isolation
- enforce policy for credentials, API requests, MCP tools, files, commands, and dependencies
- manage access with scoped roles, teams, and API keys
- track secret changes and access decisions with changelog and audit workflows
- detect exposed or hard-coded secrets before they ship
- deliver secrets and environment context through the dashboard, CLI, SDKs, API, and integrations
Core model
The platform is organized around a few core concepts:
- Workspace: The top-level space for your company or team, including members, teams, billing, and shared settings.
- Project: A container for an application or service.
- Environment: A scoped set of secrets and configuration values inside a project, such as development, staging, or production.
- Secrets: Secure key-value configuration, organized by environment and tracked through change history.
- Policies: Controls that define how credentials and agent-accessible resources can be used.
This structure keeps environments separate, access scoped, and workflows consistent across applications, services, and coding agents.
Platform surfaces
Use Stashbase through the interface that fits the work:
- Dashboard for secret management, access control, and audit workflows.
- CLI for local development, automation, and generating value-free environment schemas for coding agents.
- SDKs and REST API for application-side tooling and custom integrations.
- Agent Proxy for policy-controlled access to credentials, APIs, tools, files, commands, and dependencies.
- MCP server for AI-assisted workflows in compatible clients.
- Scanning for finding exposed or hard-coded secrets.
If you are new to Stashbase, start with Overview and then continue to the Basics section.