Skip to main content

Session Vault

Session Vault saves your agents’ conversations, encrypted, into a git remote you own, and lets another machine pick a conversation up where it left off. Overdeck never sees the contents: everything is encrypted on your machine with a key only you hold, and pan vault commands send no telemetry. It also works without the dashboard: npm install -g @overdeck/core, then pan vault on any machine.

Set up the first machine

  1. Create an empty private repository anywhere you trust (GitHub, GitLab, a NAS, your own server). Overdeck never provides or defaults a backend.
  2. Run:
  3. Write down the 24-word recovery phrase it prints. It is shown only once.
The recovery phrase is the vault key. Anyone with these words can read your vault. Losing every device and these words loses the vault: there is no recovery on any server.
Add --hooks to register a Claude Code Stop hook that saves after every turn:

Join from a second machine

Enter the 24 words when prompted (or pass --phrase-file <path>). A wrong phrase prints The recovery phrase does not match this vault. and writes nothing.

Save and sync

If a new line contains something that looks like a credential, the save is blocked and the output names the line number and pattern, never the value. Rotate the secret if it is real, then run pan vault allow-secret <id> <line> or pan vault exclude --session <id>.

Continue on another machine

resume compares the target directory’s git state with the state saved with the conversation. If the branch, commit or dirty state differs, it asks whether to continue, continue with a short note as the first message, or cancel. Use --on-drift continue|note|cancel in scripts and --no-launch to print the command instead of running it. Claude Code and Codex resume natively. Other harnesses receive a markdown digest of the conversation in the target directory to paste into a new session.

Exclude what should never leave the machine

Free local disk space (optional)

Transcripts can grow to tens of gigabytes. Eviction is off by default and never deletes anything on its own. To use it:
  1. Set "evict": true in ~/.overdeck/vault/config.json.
  2. Run pan vault evict. It lists every transcript whose contents are fully in the vault and verified by reading them back, with a fingerprint of that list. Nothing is deleted.
  3. Run pan vault evict --confirm <fingerprint> to delete exactly those files. Anything that changed since the review is skipped, and a changed list is refused with a new fingerprint.
  4. pan vault restore <id> rebuilds any evicted transcript byte for byte.
pan vault evict --decline <id> keeps a transcript out of future lists; --clear empties the list without deleting anything.

Where things live

The developer reference, including the wire format and the module map, is docs/SESSION-VAULT.md.