.env files with a secrets manager you self-host on Cloudflare. Prefix your commands with sigillo run and secrets are injected as environment variables, never written to disk.This is kldzj/sigillo, a fork of remorses/sigillo that keeps building on it for teams who want tighter control over their secrets, with features such as passkey approval for production, a signed history of every change and read, and machine tokens for CI. Some of them are opinionated in ways upstream may not want, so they live here, while fixes that suit both go upstream as pull requests. The releases list everything the fork adds. There is no hosted service: every instance runs on your own Cloudflare account with its own Google login. The CLI is published as@kldzj/sigillo, and the docs are at sigillo.kldzj.dev.
# instead of this source .env && next dev # do this sigillo run -- next dev
┌────────────────┐ sigillo run -- next dev │ App Worker │ │ │ (your account) │ │ 1. fetch secrets │ │ │──────────────────────────────────────▶│ decrypt │ │ { DB_URL, API_KEY, ... } │ AES-256-GCM │ │◀──────────────────────────────────────│ │ │ └────────────────┘ │ 2. spawn child with env vars │ ▼ ┌──────────────┐ │ next dev │ │ (child) │ └──────┬───────┘ │ │ 3. stdout / stderr ▼ ┌───────────────┐ │ redaction │ high-entropy values replaced with * │ filter │ secrets never reach your terminal └──────┬────────┘ │ ▼ terminal (safe output)
.env files: secrets live in the cloud and are easy to share across machines. No more "can you send me the .env?" on Slack..env files or pasting keys in DMs.-c prod..env files, use sigillo run to inject secrets into processes without exposing them.sigillo run replaces secret values that look random in stdout/stderr with *, so keys and tokens stay out of your chat context window. Even if an agent runs printenv, it won't see them in the output.npx -y skills add kldzj/sigillo
~/.sigillo/bin):curl -fsSL https://raw.githubusercontent.com/kldzj/sigillo/main/app/public/install.sh | bash
npm i -g @kldzj/sigillo
npx @kldzj/sigillo run -- next dev bunx @kldzj/sigillo run -- next dev
npx @kldzj/sigillo self-host
sigillo login --api-url https://sigillo.<your-subdomain>.workers.dev
sigillo setup
~/.sigillo/config.json (not in the repo). Run it in the project root if you have a single project, or in each subfolder of a monorepo. Since the config is local to your machine, you need to run sigillo setup again after cloning the repo on a new machine. Alternatively, skip setup entirely and always pass --project and --env (or -c) flags.sigillo run -- next dev
.env files, no copy-pasting keys. Go back to your instance any time to add, edit, or rotate secrets. The next sigillo run picks them up automatically.Organization (my-company) │ ├── Project (api) │ ├── dev │ │ ├── DATABASE_URL = postgres://localhost/mydb │ │ ├── API_KEY = sk-dev-xxx │ │ └── AUTH_SECRET = random-dev-key │ ├── preview │ │ ├── DATABASE_URL = postgres://preview-host/mydb │ │ └── API_KEY = sk-preview-xxx │ └── prod │ ├── DATABASE_URL = postgres://prod-host/mydb │ └── API_KEY = sk-live-xxx │ └── Project (web) ├── dev │ └── NEXT_PUBLIC_API_URL = http://localhost:3001 └── prod └── NEXT_PUBLIC_API_URL = https://api.example.com
sigillo orgs create --name my-company
sigillo orgs # find your org ID sigillo projects create --org <ORG_ID> --name my-app
sigillo setup saves the default project and environment for the current directory. This is a local-only setting stored in ~/.sigillo/config.json, not in the repository. After setup, every sigillo run in that directory (or any subdirectory) resolves the right secrets without extra flags.# single project cd my-app sigillo setup --project <PROJECT_ID> --env dev # monorepo cd monorepo/api && sigillo setup --project api_xxx --env dev cd monorepo/web && sigillo setup --project web_xxx --env dev
sigillo setup after cloning on a new machine. If you prefer not to run setup at all, you can always pass --project and --env explicitly:sigillo run --project <PROJECT_ID> -c dev -- next dev
sigillo setup shows an interactive picker. Use --project and --env for non-interactive/CI workflows.sigillo secrets set DATABASE_URL "postgres://localhost:5432/mydb" -c dev sigillo secrets set API_KEY "" -c dev sigillo secrets set AUTH_SECRET "" -c dev
sigillo secrets set DATABASE_URL "" -c preview sigillo secrets set DATABASE_URL "" -c prod
sigillo secrets set AUTH_SECRET "$(openssl rand -base64 32)" -c dev sigillo secrets set AUTH_SECRET "$(openssl rand -base64 32)" -c preview sigillo secrets set AUTH_SECRET "$(openssl rand -base64 32)" -c prod
<your-instance>/dash/projects/<PROJECT_ID>/envs/dev to add or edit secrets from the web UI. You can toggle between environments using the tabs.sigillo secrets -c dev # list secret names (values hidden) sigillo run -c dev -- pnpm dev
| Feature | Description |
| Secret injection | sigillo run -- <cmd> injects secrets as env vars, no files on disk |
| Output redaction | High-entropy values automatically replaced with * in stdout/stderr |
| File mount | --mount .env writes secrets to the given file path, deletes it after the process exits |
| Organizations | Multi-tenant orgs with admin/member roles and invite links |
| Projects & environments | Organize secrets into projects with dev, preview and prod environments |
| Audit log | Every secret change, and in protected environments every read of a value, is recorded in hash chains your instance signs; sigillo audit verify checks them |
| Passkeys for production | Reading or changing a protected environment takes a passkey: in the browser on the spot, for the CLI on an approval page. So do admin actions in an org that has one. A stolen session or CLI login alone can't read or change it |
| API tokens | Scoped to a project and optionally some of its environments, expire after 7 to 365 days, last use and IP shown, SHA-256 hashed, shown once. Machine tokens read and change protected environments, for CI |
| Sign-in allowlist | Only the email addresses and domains you list can sign up or sign in |
| Sessions | See and end every browser and CLI login signed in as you |
| Device flow | RFC 8628 login for CLI and agents, no copy-pasting tokens |
| AES-256-GCM encryption | Every secret encrypted at rest with a random 12-byte IV |
| Download formats | Export as json, env, env-no-quotes, yaml, docker, dotnet-json, xargs |
| Web UI | Full management dashboard; a value loads only when you reveal it |
| Self-hostable | Runs on Cloudflare Workers + D1, deploy your own instance |
| REST API | OpenAPI-documented API for building custom integrations |
sigillo loginsigillo login --api-url https://my-instance.dev # interactive device flow sigillo login --token sig_xxx # save existing API token sigillo login --api-url https://my-instance.dev --scope . # scoped to current dir
sigillo login always starts a new login, also when one is saved, so run it again when the CLI says not signed in, or the session expired.sigillo setup~/.sigillo/config.json, not in the repo, so it needs to be done on each machine after cloning. Run it in the project root, or in each subfolder of a monorepo. You can skip setup entirely by always passing --project and --env flags to other commands.sigillo setup # interactive project/env picker sigillo setup --project proj_abc --env dev # non-interactive
sigillo runsigillo run -- next dev # inject secrets from the configured env sigillo run -c dev -- next dev # use the dev environment sigillo run -c preview -- next dev # use the preview environment sigillo run -c prod -- next build # use the prod environment sigillo run -- printenv # verify which vars are injected (values redacted) sigillo run --command 'echo $MY_SECRET' # shell string mode sigillo run --mount .env -- npm start # write to file, clean up after sigillo run --mount config.json --mount-format json -- next dev # mount as JSON sigillo run --disable-redaction -- ./my-script.sh # opt out of output redaction sigillo run --allow-env NODE_OPTIONS -- next build # let a secret set NODE_OPTIONS
--command when you need shell features like &&, pipes, redirects, or $VARIABLE expansion. Wrap the command in single quotes so your parent shell does not expand secret variables before Sigillo injects them.PATH, NODE_OPTIONS, LD_PRELOAD, GIT_PAGER or npm_config_registry, is skipped with a warning: anyone who can change the environment's secrets would otherwise run code on your machine. Pass --allow-env NAME to use one. Names match in any case, as they do on Windows. The list is best effort: no list of such names is complete, so a secret can still change how a program runs through a variable it doesn't know.# Wrong: your shell expands $DATABASE_URL before sigillo starts sigillo run --command "psql $DATABASE_URL -c 'select 1'" # Right: $DATABASE_URL expands inside sigillo's child shell sigillo run --command 'psql $DATABASE_URL -c "select 1"'
sigillo run, especially in package scripts. This keeps regular build flags visible while secrets still come from Sigillo.{ "scripts": { "deployment": "CLOUDFLARE_ENV=preview sigillo run -c preview --command 'vite build && wrangler deploy --env preview'" } }
* in stdout/stderr. This keeps them out of agent context windows and CI logs. Shorter or more predictable values, like a port, a hostname or a word, print as they are.sigillo run through a package manager script (pnpm run, bun run, npm run), the package manager adds node_modules/.bin to PATH before Sigillo starts. Sigillo inherits that PATH and passes it to the child process, so local binaries like vite, tsc, wrangler are all available without prefixing with pnpm exec or npx.# in package.json scripts, local bins just work: sigillo run -- vite build # vite found via node_modules/.bin sigillo run -- wrangler deploy # wrangler found via node_modules/.bin sigillo run -- tsc --noEmit # tsc found via node_modules/.bin # same with --command: sigillo run --command 'vite build && wrangler deploy'
sigillo run directly with pnpm exec or bunx:pnpm exec sigillo run -- vite dev bunx @kldzj/sigillo run -- next build
curl or npm i -g), running sigillo run outside a package manager script means node_modules/.bin is not in PATH. In that case, use the full path or prefix with npx/pnpm exec inside the child command, or run Sigillo from a package script instead.sigillo secretssigillo secrets # list secret names sigillo secrets get DATABASE_URL # get a single value sigillo secrets get DATABASE_URL --force # allow value output inside agent shells sigillo secrets set API_KEY sk-live-xxx # set a value echo "multiline\nvalue" | sigillo secrets set CERT # set from stdin sigillo secrets delete OLD_KEY # delete sigillo secrets download # download all (YAML) sigillo secrets download --format json # download as JSON sigillo secrets download --format env # download as .env
secrets get and secrets download refuse to print raw values to a terminal unless you pass --force. Prefer sigillo run or a direct pipe so secret values go straight to the tool that needs them, not into the chat context.sigillo run --command 'psql "$DATABASE_URL" -c "select 1"' sigillo secrets download --format env | fly secrets import --app my-app
sigillo projectssigillo projects # list all projects sigillo projects create --org org_abc --name my-app # create project sigillo projects get proj_abc # show project details sigillo projects update proj_abc --name new-name # rename sigillo projects delete proj_abc # delete
sigillo environmentssigillo environments # list environments sigillo environments create --project proj_abc --name Staging --slug staging # create sigillo environments rename env_abc --name Production --slug prod # rename sigillo environments delete env_abc # delete
sigillo audit verifysigillo login (API tokens are refused). The newest row of each chain is kept in ~/.sigillo/audit.json, so the next check also notices rows removed or rewritten since.sigillo audit verify -c prod
$ sigillo run -c prod -- ./deploy.sh This environment is protected: approve with your passkey. Open https://secrets.acme.com/approve and enter BCDF-GHJK Waiting for your approval... ✔ Approved for 15 minutes
only a machine token can use it: see CI / GitHub Actions.| Flag | Env var | Description |
--token <sig_xxx> | SIGILLO_TOKEN | Bearer token for auth |
--api-url <url> | SIGILLO_API_URL | Your Sigillo instance (no default; saved by sigillo login --api-url) |
--env <slug> / --config <slug> / -c <slug> | SIGILLO_ENVIRONMENT | Environment slug (e.g. dev, prod) |
--project <id> / -p <id> | SIGILLO_PROJECT | Project ID or name override |
| Format | Flag | Use case |
json | --format json | Application config files |
env | --format env | Shell scripts with quotes |
env-no-quotes | --format env-no-quotes | Shell scripts without quotes |
yaml | --format yaml | Default CLI output |
docker | --format docker | Docker --env-file |
dotnet-json | --format dotnet-json | .NET appsettings.json (uses __ for nested keys) |
xargs | --format xargs | NUL-delimited pairs for shell pipelines |
wrangler secret bulk:sigillo secrets download -c prod --format env | wrangler secret bulk --env=""
.env file remains on disk. Use an
explicit empty environment for the top-level production Worker; Wrangler warns
when a configuration has named environments but the target is ambiguous.package.json scripts so you can sync before each deploy:{ "scripts": { "secrets:preview": "sigillo secrets download -c preview --format env | wrangler secret bulk --env preview", "secrets:production": "sigillo secrets download -c prod --format env | wrangler secret bulk --env=\"\"" } }
dev,
preview, and prod values separate in Sigillo, then use the matching
Wrangler environment at deployment time.vercel env add only accepts one variable at a time. Use the xargs format to pipe them:sigillo secrets download -c prod --format xargs | \ xargs -0 -n2 sh -c 'printf %s "$2" | vercel env add "$1" production --force' sh
--sensitive to mark values as sensitive in Vercel:sigillo secrets download -c prod --format xargs | \ xargs -0 -n2 sh -c 'printf %s "$2" | vercel env add "$1" production --sensitive --force' sh
package.json script:{ "scripts": { "secrets:vercel": "sigillo secrets download -c prod --format xargs | xargs -0 -n2 sh -c 'printf %s \"$2\" | vercel env add \"$1\" production --sensitive --force' sh" } }
fly secrets import reads NAME=VALUE pairs from stdin. Pipe sigillo secrets download directly, no temp file needed:sigillo secrets download -c prod --format env | fly secrets import --app my-app
fly secrets import triggers a machine restart once secrets are staged. Use --stage to skip the restart and deploy separately:# stage without restarting sigillo secrets download -c prod --format env | fly secrets import --app my-app --stage # then deploy when ready fly deploy --app my-app
package.json scripts:{ "scripts": { "secrets:fly:production": "sigillo secrets download -c prod --format env | fly secrets import --app my-app", "secrets:fly:preview": "sigillo secrets download -c preview --format env | fly secrets import --app my-app-staging" } }
sigillo secrets download --format docker > .env.docker docker run --env-file .env.docker my-image
sigillo run -- docker compose up
401 API token expired. To read or change a protected environment, an org admin checks Machine token when creating it: that takes their passkey, and the token expires after 90 days at most.- name: Run with secrets env: SIGILLO_API_URL: ${{ vars.SIGILLO_API_URL }} SIGILLO_TOKEN: ${{ secrets.SIGILLO_TOKEN }} SIGILLO_PROJECT: ${{ vars.SIGILLO_PROJECT }} SIGILLO_ENVIRONMENT: ${{ vars.SIGILLO_ENVIRONMENT }} run: | npx @kldzj/sigillo run -- next build
__ become nested objects):sigillo secrets download --format dotnet-json > appsettings.Secrets.json
DB__HOST=localhost becomes { "Db": { "Host": "localhost" } }.Your Cloudflare account ┌──────────────────────┐ ┌──────────────────────┐ │ App Worker │ OAuth │ Provider Worker │ │ (your secrets) │────────────▶│ (your login) │ │ │ PKCE │ │ │ <name> │◀────────────│ <name>-auth │──▶ Google └──────────────────────┘ └──────────────────────┘
npx @kldzj/sigillo self-host
wrangler login when present, or an OAuth browser flow, or a pre-filled API token link that works over SSH), deploys both Workers with their D1 databases, applies migrations, and prints your instance URL. A new deployment needs a Google OAuth client for its login provider: the command prints the redirect URI to register at Google Cloud credentials and asks for the client ID and secret. It also asks who may sign in (--allowed-users), and for a passphrase that encrypts ~/.sigillo/selfhost.json, the file with your deployment's keys. Re-run the same command anytime to update — only new migrations are applied and no secret is ever rotated.# non-interactive (CI/agents) CLOUDFLARE_API_TOKEN=xxx SIGILLO_SELFHOST_PASSPHRASE=xxx npx @kldzj/sigillo self-host --yes \ --google-client-id xxx.apps.googleusercontent.com --google-client-secret xxx \ --allowed-users acme.com # custom worker name and domain npx @kldzj/sigillo self-host --name sigillo --domain secrets.acme.com
git clone https://github.com/kldzj/sigillo.git cd sigillo && pnpm install
provider/.dev.vars (requires a Google OAuth client with <provider-url>/api/auth/callback/google as redirect URI):BETTER_AUTH_SECRET=<any random string> GOOGLE_CLIENT_ID=<your Google OAuth client ID> GOOGLE_CLIENT_SECRET=<your Google OAuth client secret>
app/.dev.vars:BETTER_AUTH_SECRET=<any random string> ENCRYPTION_KEY=<output of: openssl rand -base64 32>
ALLOWED_USERS=acme.com,ops@partner.io in both files, and as a secret on both Workers when you deploy.pnpm --dir provider dev pnpm --dir app dev
provider/wrangler.jsonc and app/wrangler.jsonc (your D1 databases, BETTER_AUTH_URL for the provider and PROVIDER_URL for the app, plus the global_fetch_strictly_public compatibility flag on the app when both Workers share a workers.dev subdomain), then deploy the provider first and the app second.┌─────────────────────────────────────────────────────────────────┐ │ Your Machine │ │ │ │ sigillo run -- next dev │ │ │ │ │ │ device flow login (RFC 8628) │ │ │ or bearer token │ │ ▼ │ │ ┌──────────┐ │ │ │ Sigillo │ │ │ │ CLI │ │ │ └────┬─────┘ │ │ │ │ └───────┼─────────────────────────────────────────────────────────┘ │ REST API ▼ ┌──────────────────────┐ ┌──────────────────────┐ │ App Worker │ │ Provider Worker │ │ (self-hosted) │────────▶│ (self-hosted) │ │ │ OAuth │ │ │ • Secrets CRUD │ PKCE │ • Google login │ │ • AES-256-GCM │ │ • OAuth2 / OIDC │ │ • Audit log │◀────────│ • Dynamic client │ │ • API tokens │ token │ registration │ │ • Device flow │ │ │ │ ┌────────────┐ │ │ ┌────────────┐ │ │ │ D1 (app) │ │ │ │ D1 (auth) │ │ │ └────────────┘ │ │ └────────────┘ │ └──────────────────────┘ └──────────────────────┘
CLI/Agent App (self-hosted) Provider (self-hosted) │ │ │ │ POST /api/auth/device/code │ │ │─────────────────────────────▶│ │ │ { user_code, device_code } │ │ │◀─────────────────────────────│ │ │ │ │ │ User opens /device │ │ │ and enters user_code │ │ │ ┌────────────────────┼────── redirect ───────────────▶│ │ │ │ │ │ │ │ Google sign-in ──▶│ Google │ │ │ ◀── callback ─────│ │ │ │ │ │ │ │◀── auth code (PKCE) ───────────│ │ └────────────────────┼────── approved ───────────────▶│ │ │ │ │ Poll /api/auth/device/token │ │ │─────────────────────────────▶│ │ │ { access_token } │ │ │◀─────────────────────────────│ │
Local development CI / GitHub Actions ───────────────── ─────────────────── sigillo login SIGILLO_TOKEN=sig_xxx │ │ ▼ │ Browser opens /device │ │ │ ▼ │ Enter user_code │ │ │ ▼ │ Google sign-in │ │ │ ▼ ▼ Signed session token saved Bearer token from env in ~/.sigillo/config.json var or GitHub secret │ │ ▼ ▼ sigillo run -- next dev sigillo run -- next build
sigillo login once, then the session is reused until it expires or you end it on the Sessions page.SIGILLO_TOKEN as a secret in your CI provider. No browser needed, no interactive prompts.ENCRYPTION_KEY: 32 random bytes, base64-encoded (openssl rand -base64 32)BETTER_AUTH_SECRET via SHA-256 (default if ENCRYPTION_KEY is not set)plaintext value ("sk-live-xxx") │ ▼ ┌─────────────┐ ┌──────────────┐ │ AES-256-GCM │◀────│ 12-byte │ │ encrypt │ │ random IV │ └──────┬──────┘ └──────────────┘ │ ▼ ┌──────────────────────────────────┐ │ secret_event (append-only row) │ │ │ │ operation: "set" │ │ name: "API_KEY" │ │ value_encrypted: <ciphertext> │ │ iv: <12 bytes> │ │ actor: "user:usr_abc" │ │ seq, hash, row in the │ │ signature: signed chain │ └──────────────────────────────────┘
sigillo audit verify./api/v0/openapi.json.# list secrets curl -H "Authorization: Bearer sig_xxx" \ https://<your-instance>/api/v0/projects/{projectId}/environments/{environmentId}/secrets # set a secret curl -X POST -H "Authorization: Bearer sig_xxx" \ -H "Content-Type: application/json" \ -d '{"name": "API_KEY", "value": "sk-live-xxx"}' \ https://<your-instance>/api/v0/projects/{projectId}/environments/{environmentId}/secrets # bulk download as JSON curl -H "Authorization: Bearer sig_xxx" \ https://<your-instance>/api/v0/projects/{projectId}/environments/{environmentId}/secrets/download?format=json # bulk set curl -X PUT -H "Authorization: Bearer sig_xxx" \ -H "Content-Type: application/json" \ -d '{"secrets": {"KEY1": "val1", "KEY2": "val2"}}' \ https://<your-instance>/api/v0/projects/{projectId}/environments/{environmentId}/secrets