@secret-sync/cli
v0.2.7
Published
Encrypted secret synchronization for people, services, and AI agents
Readme
Secret Sync CLI
The official command-line interface and local MCP server for Secret Sync.
Install
npm install --global @secret-sync/cliOr pin it inside a repository:
npm install --save-dev --save-exact @secret-sync/cliAuthenticate
secret-sync loginThe device flow opens secret-sync.com for approval and stores the resulting
token in the native OS credential store. The mode-0600 local configuration
contains only the bound service origin. CI and other unattended processes may
instead provide a scoped SECRET_SYNC_TOKEN; machine tokens are always pinned
to https://secret-sync.com.
Use
secret-sync pull --environment dev --only-keys API_KEY,DATABASE_URL --output .env.local
secret-sync run --environment dev --only-keys API_KEY,DATABASE_URL -- your-command
secret-sync run --environment dev --only-keys API_KEY,DATABASE_URL --watch -- your-command
secret-sync access-keys create \
--organization <organization-id> \
--name "Local MCP" \
--profile agent_metadata \
--environment <environment-id> \
--credential mcp
secret-sync mcp --credential mcpRepository aliases such as dev and prod are resolved from the tracked
.secret-sync.json file only for server-bounded machine credentials. An
interactive session must use an explicit environment UUID, so a cloned
repository cannot redirect a human mutation. That tracked file cannot choose a
service origin.
run and watch inject values directly into the child process and never create
a default env file. The MCP server is read-only and metadata-only: secret
values and mutation tools are unavailable by construction.
See the agent-oriented documentation for the full command and security contracts.
