Trash
Recover deleted secrets for 30 days, restore them to their original projects, or remove them permanently.
Trash gives every deleted secret a 30-day recovery window. From one place, you can find deleted secrets, see who or what deleted them, restore them to their original project, or remove them permanently.
A deleted secret becomes unavailable to applications and machines immediately. Restore it before its retention countdown ends if you need it again.
#How Trash works
When a secret is deleted, SikkerKey removes it from active use and places its encrypted record in Trash. The secret keeps its name, ID, current value, original project, and version history throughout the recovery window.
Stage | What happens |
|---|---|
Deleted | The secret leaves active use immediately. Existing machine grants are removed and attached secret operations stop. |
In Trash | The secret remains recoverable for 30 days. Trash shows its deletion details and remaining time. |
Restored | The secret returns to its original project with the same ID, value, and version history. |
Permanently deleted | The secret record and all of its versions are removed and can no longer be restored from Trash. |
Secrets can arrive in Trash after a member or AI agent deletes them. Secrets governed by a time limit or a maximum-read policy also move to Trash when that limit is reached.
#Open and review Trash
Open Trash from the dashboard sidebar.
Use the search field to find a secret by name or secret ID.
Review the original project, deletion time, deleting actor, and retention countdown.
Open the row menu to restore the secret or delete it permanently.
Deleted secrets are listed with the newest deletion first. The table provides the following details:
Name and ID — identify the secret and copy its ID when needed.
Project — shows where the secret will return when restored.
Type — shows the application that contains the project, or Standalone for an independent project.
Deleted — shows how long ago the deletion occurred.
Deleted by — identifies the member, AI agent, or automated policy responsible for the deletion.
Remaining — shows the number of days left before permanent removal. The countdown changes from blue to amber and then red as the deadline approaches.
Search by secret ID when several deleted secrets share similar names. A restored secret keeps that same ID.
#Restore a secret
Find the secret in Trash.
Open its row menu and select Restore.
Return to the original project and confirm that the secret is available.
Reapply the machine access and operational settings the secret needs.
Restoration returns the secret to the project it belonged to before deletion. The original project must still exist.
Deletion removes access grants and stops attached operations to prevent a deleted secret from continuing to serve workloads. After restoration, review and reapply the settings that are relevant to the secret, including:
machine access grants;
rotation schedules;
synchronized or managed-secret connections; and
leased credential setup.
Deleted canaries are replaced rather than restored. Create a new canary so it receives a fresh trigger and notification setup.
#Restore multiple secrets
Use the checkboxes to restore several secrets from the current page together.
Select each secret you want to recover, or use the checkbox in the table heading to select the page.
Select Restore.
Wait for the restore operation to finish.
Open each original project and reapply the required access and operational settings.
Bulk actions apply to the secrets selected on the current page. Search first when you want to work with a specific group.
#Permanently delete secrets
Permanent deletion removes the selected secret and all of its version history from the vault. This action cannot be undone from Trash.
Find the secret in Trash.
Open its row menu and select Delete permanently.
Review the confirmation, including the secret name.
Select Delete Forever.
To remove several secrets together, select their checkboxes and choose Delete. The confirmation lists every selected secret before you continue.
Permanent deletion is immediate. Confirm that no recovery, historical version, or audit investigation requires the secret before selecting Delete Forever.
#Understand the 30-day retention period
The recovery period begins at the recorded deletion time. Trash calculates the removal date by adding 30 days and displays the remaining whole days in the table.
More than 7 days remaining appears in blue.
7 days or fewer appears in amber.
2 days or fewer appears in red.
On the final day, the countdown shows today.
Once a secret reaches the end of the 30-day window, SikkerKey’s regular cleanup removes it permanently. Restore important secrets before the countdown reaches its final day.
#Secrets deleted by access policies
An access policy can move a secret to Trash automatically when its configured lifetime expires or when its maximum number of reads is reached.
For a time limit, SikkerKey evaluates expiry regularly and records the automated deletion.
For a maximum-read limit, the read that reaches the configured maximum succeeds, then the secret moves to Trash. Later reads are blocked.
The normal 30-day Trash recovery window begins when the automated deletion occurs.
The Deleted by column identifies these entries as automated actions, making them easy to distinguish from member-initiated deletions.
#Control access to Trash
Vault owners can view and manage every deleted secret. Organization members receive Trash access through their vault role.
Manage own trashed secrets lets a member view, restore, and permanently delete secrets that they personally deleted.
Manage all trashed secrets lets a member view, restore, and permanently delete every secret in the vault’s Trash, including deletions made by other members, AI agents, and automated policies.
These permissions apply across the vault, so the Trash view can provide one recovery workspace for all projects.
#Review Trash activity
SikkerKey records the secret lifecycle in the Audit Log so you can follow a deletion from the initial action through recovery or final removal.
Secret Delete records a member or AI-agent deletion that moves a secret to Trash.
Secret Destroyed records deletion caused by a time or read limit.
Secret Restore records recovery to the original project.
Secret Hard Delete records a manual permanent deletion.
Trash Cleanup records automatic removal after the 30-day retention period.
Use the Audit Log’s action, actor, secret, project, and time filters to investigate Trash activity and confirm the outcome of a restore or permanent deletion.
#Recover a deleted secret safely
Search Trash by the secret name or ID.
Confirm the original project, deleting actor, and time remaining.
Restore the secret.
Reapply machine grants and any required rotation, synchronization, managed-secret, or leased credential settings.
Verify that the intended workload can read the secret.
Review the Secret Restore event in the Audit Log.