Authentication
vault CLI works here without extra configuration.
Paths
The path after the provider segment is the Vault path, including the mount:data key internally; SecRefs unwraps that for you,
so #key refers to your field rather than Vault’s envelope.