Our MCP server resolves that against a shared team namespace, and falls back to a private one when it can't reach it.
It never fails silently: every result says which source it used (Namespace: team|local).
When two teammates' AI agents mask the same identifier, they should get the same placeholder - not two different ones that each look equally plausible.
The crypto lives once, in the engine both the browser and CLI share. vault-parity.test.ts opens a fixture the browser produced and proves the CLI opens it the same way β no second implementation to quietly drift.
Our CLI can now push/pull maps to Cloud (paid team feature) β and the vault key is derived from your passphrase locally, never sent. Zero-knowledge, not "trust us."
Our MCP server resolves that against a shared team namespace, and falls back to a private one when it can't reach it.
It never fails silently: every result says which source it used (Namespace: team|local).