Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
envsec — Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager) | Kitploit
Tools/GitHubGitHub/davidnussio/envsec
Authentication & AuthorizationGeneral Purpose UtilitiesEncryption/Decryption ToolsCloud SecurityDevSecOpsSecret Detection
GitHubdavidnussio/envsec

envsec

Secure CLI tool for managing environment secrets using native OS credential stores (macOS Keychain, Linux Secret Service, Windows Credential Manager)

View Repository
15191 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

envsec

Secure environment secrets management using native OS credential stores.

Demo

Image

Features

  • Store secrets in your OS native credential store (not plain text files)
  • Cross-platform: macOS, Linux, Windows
  • Organize secrets by context (e.g. myapp.dev, stripe-api.prod, work.staging)
  • Track secret metadata (key names, timestamps) via SQLite
  • Search contexts and secrets with glob patterns
  • Run commands with secret interpolation
  • Save and rerun commands with cmd (search, list, run, delete)
  • Export secrets to .env files (with generation tracking via audit)
  • Export secrets as shell environment variables (eval $(envsec env))
  • Load secrets from .env files (with conflict detection)
  • Share secrets encrypted with GPG for team members
  • Interactive terminal UI (envsec tui) for managing secrets without memorizing commands

Packages

This is a monorepo containing the following packages:

PackageDescriptionnpm
envsecCLI tool for managing secretsnpm
@envsec/sdkNode.js / Bun SDK for loading secrets programmaticallynpm
@envsec/coreCore engine — OS credential store adapters + metadata DBnpm
@envsec/tuiInteractive terminal UI for secrets managementnpm

SDK Quick Start

For programmatic access to secrets from Node.js or Bun, use @envsec/sdk:

npm install @envsec/sdk
import { loadSecrets } from "@envsec/sdk";

// Load and inject into process.env
await loadSecrets({ context: "myapp.dev", inject: true });

// Or use the client for full control
import { EnvsecClient } from "@envsec/sdk";
const client = await EnvsecClient.create({ context: "myapp.dev" });
const apiKey = await client.get("api.key");
await client.close();

See the full SDK documentation for all APIs, multi-context support, and options.

Requirements

  • Node.js >= 22

macOS

No extra dependencies. Uses the built-in Keychain via the security CLI tool.

Linux

Requires libsecret-tools (provides the secret-tool command), which talks to GNOME Keyring, KDE Wallet, or any Secret Service API provider via D-Bus.

# Debian / Ubuntu
sudo apt install libsecret-tools

# Fedora
sudo dnf install libsecret

# Arch
sudo pacman -S libsecret

A running D-Bus session and a keyring daemon (e.g. gnome-keyring-daemon) must be active. Most desktop environments handle this automatically.

Windows

No extra dependencies. Uses the built-in Windows Credential Manager via cmdkey and PowerShell.

Installation

Homebrew (macOS / Linux)

brew tap davidnussio/homebrew-tap
brew install envsec

npm

npm install -g envsec

npx (no install)

npx envsec

mise

mise use -g npm:envsec

Usage

Most commands require a context specified with --context (or -c). A context is a free-form label for grouping secrets — e.g. myapp.dev, stripe-api.prod, work.staging.

Global options

These options are available on all commands:

  • --context, -c — Context name (e.g. myapp.dev, stripe-api.prod). Also reads ENVSEC_CONTEXT env var
  • --debug, -d — Enable debug logging
  • --json — Output in JSON format for scripting
  • --db — Path to SQLite database file (default: ~/.envsec/store.sqlite). Also reads ENVSEC_DB env var

Custom database path

By default, metadata is stored at ~/.envsec/store.sqlite. You can override this with --db or the ENVSEC_DB environment variable:

# Use a project-local database
envsec --db ./local-store.sqlite -c myapp.dev list

# Or via environment variable
export ENVSEC_DB=/shared/team/envsec.sqlite
envsec -c myapp.dev list

The --db flag takes precedence over ENVSEC_DB. Use cases include per-project databases, team-shared databases on network drives, and CI/CD with ephemeral storage.

Add a secret

Store a secret in the OS credential store.

  • <key> — Secret key name (e.g. api.key, db.password)
  • --value, -v — Value to store (omit for interactive masked prompt)
  • --expires, -e — Expiry duration (e.g. 30m, 2h, 7d, 4w, 3mo, 1y)
# Store a value inline
envsec -c myapp.dev add api.key --value "sk-abc123"

# Or use the short alias
envsec -c myapp.dev add api.key -v "sk-abc123"

# Omit --value for an interactive masked prompt
envsec -c myapp.dev add api.key

# Set an expiry duration with --expires (-e)
envsec -c myapp.dev add api.key -v "sk-abc123" --expires 30d

# Supported duration units: m (minutes), h (hours), d (days), w (weeks), mo (months), y (years)
# Combinable: 1y6mo, 2w3d, 1d12h
envsec -c myapp.dev add api.key -v "sk-abc123" -e 6mo

Get a secret

Retrieve a secret value from the OS credential store.

  • <key> — Secret key name to retrieve
  • --quiet, -q — Print only the raw value (no warnings or extra output)
  • --json — Output in JSON format (includes context, key, value, expires_at)
envsec -c myapp.dev get api.key

# Print only the raw value (no warnings or extra output)
envsec -c myapp.dev get api.key --quiet
envsec -c myapp.dev get api.key -q

Delete a secret

Remove a secret from the OS credential store.

  • <key> — Secret key name to delete (optional if --all is used)
  • --yes, -y — Skip confirmation prompt
  • --all — Delete all secrets in the context
envsec -c myapp.dev delete api.key

# or use the alias
envsec -c myapp.dev del api.key

Rename a secret

Rename a secret key within the same context. The value and expiry metadata are preserved.

  • <old-key> — Current secret key name
  • <new-key> — New secret key name
  • --force, -f — Overwrite target if it already exists
# Rename a key
envsec -c myapp.dev rename old.key new.key

# Overwrite target if it already exists
envsec -c myapp.dev rename old.key existing.key --force

List all secrets in a context

List all secret keys and metadata in a context.

  • --json — Output in JSON format
envsec -c myapp.dev list

List all contexts

List all available contexts with secret counts.

  • --json — Output in JSON format
# Without --context, lists all available contexts with secret counts
envsec list

Search secrets

Search secrets or contexts using glob patterns.

  • <pattern> — Glob pattern to search for (e.g. api.*, myapp.*)
  • --json — Output in JSON format
# Search secrets within a context
envsec -c myapp.dev search "api.*"

# Search contexts by pattern (without --context)
envsec search "myapp.*"

Move secrets between contexts

Move secrets from one context to another. The source secrets are removed after moving.

  • <pattern> — Glob pattern or exact key to move (optional if --all is used)
  • --to, -t — Target context to move secrets to
  • --all — Move all secrets from source context
  • --force, -f — Overwrite existing secrets in the target context
  • --yes, -y — Skip confirmation prompt
# Move a single secret
envsec -c myapp.dev move api.token --to myapp.prod
Download Tool