
A modern git based age-encrypted secrets manager for teams.
cottage is a GitOps tool for teams to manage age-encrypted secrets in git repositories.
It provides a simple workflow to encrypt/decrypt secrets, manage recipients, and keep secrets out of the repo while still allowing for easy sharing via VCS. cottage also generates redacted previews of encrypted secrets for better visibility and supports both persistent and temporary decryption workflows, while ensuring secrets are never committed in plaintext.

.gitignore to keep unencrypted secrets out of the repo.ctg diff shows diff of locally modified secrets with tracked encrypted counterparts.ctg decrypt/sync keeps decrypted secrets on disk.ctg run (shortcut ctgx) and ctg edit decrypt secrets before the operation, keeping them on disk if already present beforehand or automatically cleaning them up afterwards if they were not.ctg encrypt --clean, ctg run --clean, and ctg edit --clean ensure that decrypted files are cleaned up from disk even if they were present before.ctg env injects decrypted secrets as environment variables to run a command, without writing them to disk at all.ctg cat PATH decrypts in memory and prints to stdout for direct stdin piping to other tools.ctg clean deletes all decrypted secrets from local repo to let you run your AI agents with a tiny bit less worry.ctg init turns any directory into a secret store.ctg pull/diff/push like git pull/diff/push.# rust: cargo-binstall/cargo
cargo binstall --locked cottage
cargo install --locked cottage
# python: pip/uv/uvx
pip install cottage
uv pip install cottage
uvx --from cottage ctg --version
# node: yarn/pnpm/npx
yarn global add @sayanarijit/cottage
pnpm add -g @sayanarijit/cottage
npx -p @sayanarijit/cottage ctg --version
Also available as docker images:
# Docker
docker run --rm -v $PWD:/app sayanarijit/cottage --version
# Podman
podman run --rm -v $PWD:/app quay.io/sayanarijit/cottage --version
Or download the latest release from GitHub.
Use the Cottage VS Code extension to install ctg, add Copilot safety hooks, encrypt files from the Explorer, and open .cott.age files through the editor workflow.
Install it from the Visual Studio Marketplace, or build and install it locally from vscode-plugin-cottage.
Download the VSX file and install it in your Cursor or Eclipse IDE. It works similar to the VS Code extension.
Use the cottage.vim plugin to encrypt/decrypt secrets from Vim or Neovim.
All of the integrations below keep AI agents from running ctg/ctgx directly and from viewing or editing secret files: anything inside .cottage/, any *.cott.* file (encrypted *.cott.age blobs and redacted *.cott.toml previews), and any decrypted file that still has a *.cott.age counterpart on disk.
If you are using Claude Code, add .claude/settings.json and .claude/hooks/deny-secrets.py to your repos with secrets so Claude Code sessions handle secrets safely, or install the claude-plugin-cottage plugin.