hushsecrets your AI agent can use but never readGitHub

When two branches both change the vault

Two people adding keys on two branches is ordinary; a vault file that conflicts as a wall of base64 is not something anyone can resolve by eye. hush merges it key by key:

hush merge-driver --install   # once per clone: git hands vault merges to hush

After that, a git merge or git pull that touches .hush/vault.json just works — keys added on each side are kept, a rotation or a removal on one branch wins and everything from the other branch is re-sealed under the new key, and a member added on one branch while the other rotated is given the new key. When both branches changed the same key differently, git stops, the file keeps your branch's value, and you choose:

hush merge status                    # set, key, who changed it on each side, when — never a value
hush merge pick STRIPE_KEY --theirs  # or --ours

Both branches rotating the key (two revocations) is never merged automatically.

The driver is switched on per clone, in .git/info/attributes and your git config, never in a committed file: git falls back to a line-by-line text merge when a named driver is not configured, which could quietly break a vault. A teammate who has not installed it still gets a safe conflict, and hush merge finishes it.