~/.sigillo/bin:curl -fsSL https://raw.githubusercontent.com/kldzj/sigillo/main/app/public/install.sh | bash
npm i -g @kldzj/sigillo
npx @kldzj/sigillo run -- next dev bunx @kldzj/sigillo run -- next dev
sigillo login --api-url https://sigillo.<your-subdomain>.workers.dev
~/.sigillo/config.json, and later commands reuse it. When one says not signed in, or the session expired, run sigillo login again.sigillo orgs create --name my-company sigillo orgs # shows the organization's ID sigillo projects create --org <ORG_ID> --name my-app
sigillo setup saves the project and environment for the current directory, so commands there don't need flags:sigillo setup # pick them interactively sigillo setup --project <PROJECT_ID> --env dev # or name them
cd monorepo/api && sigillo setup --project <API_PROJECT_ID> --env dev cd monorepo/web && sigillo setup --project <WEB_PROJECT_ID> --env dev
~/.sigillo/config.json on your machine, not in the repository, so run sigillo setup again after cloning on another machine. You can also skip it and pass --project and -c to every command.sigillo secrets set DATABASE_URL "postgres://localhost:5432/mydb" -c dev sigillo secrets set API_KEY "" -c dev
sigillo secrets set AUTH_SECRET "$(openssl rand -base64 32)" -c dev
sigillo secrets -c dev # the names, without values sigillo run -- next dev # your app, with the secrets as environment variables
.env file, and nothing to copy. Change a value on your instance, and the next sigillo run picks it up.npx -y skills add kldzj/sigillo
sigillo run instead of reading .env files: the command gets the secrets, and its output reaches the agent with values that look random replaced by *, even after printenv. Inside an agent's shell, sigillo secrets get and sigillo secrets download refuse to print values unless you pass --force.