The open source
secret manager for teams.
Projects, environments and every value in them. Encrypted, compared, and one command away.
$ npm i -g secmgrWhy secmgr
Secrets do not belong in Slack threads, in a .env someone emailed in 2021, or in a doc called passwords-final. They belong somewhere quiet, where every change has an author and nothing leaks by accident.
01Import
Paste a .env.
That is the import.
Paste anywhere on the page or drop the file. Every line is parsed and sorted into new, changed and invalid before a single value is written.
- ⌘VPaste anywhere to open the import
- Conflicts wait for you: overwrite or skip, per key
02Compare
See drift before production does.
Line up development, staging and production side by side. Missing keys, values that differ and live keys where they do not belong surface on their own.
- Add a missing key to production in one click
- Values stay masked until you reveal them
03CLI
One command.
Every environment.
Run any process with the environment injected. No .env on disk, nothing to commit by accident, the same command on a laptop and in CI.
secmgr run --env staging -- npm run devsecmgr diff staging productionsecmgr pull --env production > .env
04Activity
Every change has an author.
Every read, reveal and edit is recorded with who, which key, which environment and when. Open any entry to see exactly what changed.
- Filter by member, action or environment
- Service tokens are named, scoped and logged too
Everything else
Everything a secret needs.
Nothing it does not.
Encrypted at rest
Every value is sealed with AES-256-GCM under its project's own key. The database only ever holds ciphertext.
Protected environments
Production carries a lock. Saving to it asks you to type its name first.
Rotation reminders
Rotate every N days per secret. A badge appears the day a key is due.
One-time share links
Send a single value through a link that expires after one view or 24 hours.
Command menu
Press ⌘K to jump to any project, environment or secret, or run an action.
Audit log
Who did what to which key in which environment, and when. Each entry opens its diff.
CLI and CI tokens
Scoped service tokens, read or read and write, with expiry and last used.
Self-host with Docker
Run the whole thing on your own infrastructure from a single container.
Open source
Read every line.
Run it yourself.
secmgr is developed in the open. File an issue, send a patch, or keep every secret on hardware you control.
# Run secmgr with a persistent volume
$ docker run -d -p 3000:3000 \
-v secmgr-data:/data \
ghcr.io/secmgr/secmgr
# Point the CLI at your instance
$ secmgr login --host http://localhost:3000
$ secmgr link lumen-apiThe container image is planned. Names and flags may change before the first release.