Data and storage¶
Voktty separates preferences, credentials, session history and runtime state. Platform paths are resolved through native APIs rather than by concatenating HOME or USERPROFILE.
Application identity¶
| Item | Value |
|---|---|
| Product | Voktty |
| Bundle id | dev.voktty.app |
| Keychain service | voktty |
| Session store | voktty-sessions.json |
| Extension store | voktty-extensions.json |
Secrets¶
Provider keys are read and written through secrets_get, secrets_set and secrets_delete. macOS uses Keychain and Windows uses Credential Manager through the keyring crate. Linux uses a local JSON fallback with restrictive permissions, atomic writes and no frontend access.
Keys never go into project files, the settings store, browser storage, logs or AI prompts generated by the application.
AI sessions¶
Session metadata and messages are stored with the Tauri store plugin. The session list and active id are separate from per-session message keys so message hydration can remain lazy. Switching provider keys clears the in-memory chat map while keeping persisted sessions.
Extensions¶
Extension source code is discovered under the user's .voktty/extensions directory. Enabled extension ids are stored in the application data directory. The source directory and enabled-id list are separate so disabling an extension does not delete its code.
Workspace state¶
Space and tab persistence stores roots, environments and layouts. Active SSH session ids are runtime values and are removed before persistence. Secrets must not be embedded in workspace metadata.
Runtime control data¶
The CLI control plane writes a short-lived descriptor under the user cache directory. It contains a random token, process identity and loopback endpoint. File permissions and ownership are applied for the platform, and the descriptor is removed only when it still belongs to the exiting process.
Safe cleanup¶
Use the application's own reset controls where available. Before deleting a store file manually, close Voktty and make a backup. Never delete broad home-directory paths to reset one preference, and do not remove keychain entries unless you intend to revoke credentials.