---
title: "VaultEntry"
description: "a secret, encrypted under its owner's key; never in a table, a log, an address or an event"
section: concepts
address: /concepts/vaultentry
contract: 0476e35e6e275db5
---

# VaultEntry

a secret, encrypted under its owner's key; never in a table, a log, an address or an event

[figure: VaultEntry is a definition at tenant scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | tenant |
| key | its owner and what it is for |
| store | vault |
| family | people |



## Fields


| field | type | required | note |
|---|---|---|---|
| `owner` | `one of the platform \| a tenant` | yes |  |
| `purpose` | `text` | yes |  |
| `versions` | [SecretVersion](/concepts/secretversion) | yes | each with who rotated it |
| `calls_that_may_use_it` | `[text]` | yes |  |
| `last_used_at` | `time` | no |  |
| `last_used_by_role` | `text` | no |  |
| `where_on` | `text` | yes |  |



## Routes that use it
No route takes or returns VaultEntry directly. The record holds it, and the objects that point at it reach it.
