@pinchpass/cli
v1.1.1
Published
One-time E2E-encrypted secret request links — native for Pi and OpenClaw agents
Maintainers
Readme
@pinchpass/cli
One-time E2E-encrypted secret request links for AI agents.
Generate a temporary HTTP server with a single-use encrypted form for collecting sensitive values (API keys, tokens, passwords) — locally or over the internet via a built-in bore.pub tunnel. The relay never sees the secret: encryption happens in the browser, and the decryption key lives only in the URL fragment.
Install
npm i -g @pinchpass/cliThe install downloads the prebuilt pinchpass binary for your platform to
~/.local/bin (or finds an existing install).
Pi (pi.dev)
This package is a native Pi package:
pi install npm:@pinchpass/cliThat registers:
request_secrettool — two collection modes:via: "modal"(default in the TUI): a Pi dialog collects each secret directly into.env— the value never reaches the LLM, never enters the transcript, and no server is started. Cancelable withEsc.via: "link": spawns the CLI, streams the one-time E2E-encrypted link to the user immediately, blocks until they submit or the TTL expires.viadefaults to"auto": modal in the TUI, link everywhere else.
pinchpassskill — full usage guidance for the model.
The binary is resolved from PATH, ~/.local/bin, ~/.openclaw/bin, and
~/.pi/bin — no PATH configuration required (not needed for the modal mode).
OpenClaw
Installed as a plugin, it registers the same request_secret tool. Note that
the OpenClaw path executes the CLI in the foreground: keep the exec timeout
longer than the TTL, or the link dies with the exec session.
CLI
pinchpass request <secret-name>... [flags]| Flag | Default | Description |
|------------|-----------|-----------------------------------------|
| -tunnel | false | Open a bore.pub tunnel for a public URL |
| -note | — | Description shown on the form |
| -out | .env | Output .env file path |
| -ttl | 30 | Minutes until the link expires |
| -port | random | Local port to bind |
| -json | false | Machine-readable JSON output |
License
MIT
