92e0de0ac4
Desktop - Settings → Credential Vault gains a "Password managers" section: per-manager toggle (disabled with a hint when the CLI isn't installed), Locked/Unlocked pill, Unlock (masked master-password dialog → vault.unlock) and Lock. Items from a manager show a source badge instead of a delete button. - Mid-turn vault.unlock.request renders a masked card in the chat (same contract as the secret/sudo cards: dismiss = keep locked, late answers tolerated, blocks the composer, badges background sessions). - i18n parity en/ar/ja/zh/zh-hant. Ink TUI (hermes --tui): vault.unlock.request/expire overlay via MaskedPrompt; Esc keeps the manager locked. CLI: `hermes vault sources [--enable|--disable NAME]`; `hermes vault list` shows the source column and names enabled-but-locked managers. Docs: credential-vault.md covers managers, per-session unlock, and the headless (cron/webhook/API/-q) no-prompt posture.