fingerprint is a keyed SHA-256 digest of the value: equal fingerprints within one scope mean equal values, but a workspace secret and its intern copy carry different fingerprints. hosts and fingerprint are null only for legacy rows written before host binding was required; storing the secret again assigns hosts.