TLS 1.3 mTLS TLS 1.3 mTLS Transit Consumer App vault read creds/* HashiCorp Vault :8200 · TLS cred-rotation-api :8443 · mTLS SaaS Provider Any Platform · No Native Engine Transit Engine AES-256-GCM96
Auth / Vault token
Plaintext credential ⚠
Transit ciphertext (safe)
SPIFFE JWT-SVID
Internal / plugin
🔴 → 🟢 Transit encrypts here
🟢 → 🔴 Transit decrypts here
— / —
Speed: Normal
Steps
Press Play or Step → to walk through the rotation flow.

Watch the packet turn red when a plaintext credential is in flight, and teal the moment Transit encryption is applied. The two-color transition is the security model made visible.
Request / Dispatch

        
Response