I think this is pretty sweet! It's behind a feature flag you can opt-into yourself on the docs page. If you'd prefer to keep secrets stored in your own password manager (like
@1Password or
@Bitwarden for example), you now can!
As usual, the agent can use, but not see the secret