danReynolds/keybay

Keybay: An OS-backed secret storage CLI and Dart SDK

★ 2Forks 0DartGitHub ↗Compare

Project website ↗

clidartkeychainsecretssecurity

README

Keybay

Keep local secrets out of your repository and in one encrypted store belonging to the host application.

Keybay is local-only: no account, hosted service, daemon, network path, or shell hook. The Dart SDK supports iOS, Android 12+, macOS, and ordinary Linux desktop. The CLI supports macOS and ordinary Linux desktop.

Version 0.2.0 is prepared but not yet published. The SDK and CLI/TUI source is integrated; native CLI packaging and hosted Fleury dependencies remain release gates. The SDK will ship on pub.dev and the CLI as native binaries through Homebrew and GitHub releases. See release readiness and the local CLI installation guide.

CLI

Commit a reference, not its value:

OPENAI_API_KEY=kb://my-app/openai-api-key
keybay set my-app/openai-api-key
keybay get my-app/openai-api-key
keybay run -- ./app

The CLI is one application with one store. Slash-separated key names organize records; they are not separate security domains. See the CLI guide.

Dart and Flutter

import 'package:keybay/keybay.dart';

final session = await Keybay.open();
try {
  await session.set('api-token', tokenFromOAuth);
  final token = await session.get('api-token');
} finally {
  await session.close();
}

There is no runtime application-ID or store selector. Keybay derives an OS-authenticated application identity where the platform provides one; ordinary Dart executables declare their namespace in the owning pubspec.yaml. See the SDK guide.

SDK 0.2.0 replaces the 0.1.x API and encrypted format; V1 stores are not read, migrated or removed. The release scope records deferred physical lifecycle qualification and lower-priority Argon2 performance acceptance. They are not passing qualification claims.

A retained platform root without its complete encrypted file returns storeStateConflict, including after some interrupted initializations or Apple reinstalls/restores. Follow the deliberate recovery guidance; do not automatically reset on error.

Opening, changing authentication, and resetting may invoke trusted OS/provider UI. Record operations and authentication listing never prompt.

Security

Every supported platform uses the same independently encrypted record frames and an encrypted manifest. One platform-protected root unlocks that application's store key. Applications can add a passphrase so platform access alone is insufficient.

Keybay fails closed when identity, platform protection, or authenticated store state cannot be established. It never falls back to plaintext, process memory, another provider, or pre-V2 storage. See SECURITY.md and the accepted V2 architecture RFC.

The Flatpak candidate uses authenticated sandbox identity, private ciphertext, and XDG Secret Portal protection. The repeatable Linux regression exercises two installed application IDs, including inside the tested nested Docker setup. Remaining release evidence is tracked in the security suite. It never falls back to raw Secret Service. Windows, Snap, and unsupported provider configurations fail closed. See the Linux profile, including Flatpak's retained portal secret after reset.

Development tests

Run ./tool/test_e2e.sh all for the routine SDK regressions, or select a subset such as ./tool/test_e2e.sh linux flatpak. See the platform regression guide for prerequisites, reports, CI, and the separate physical-device qualification procedures.

Pre-1.0 APIs and the file format may still change. MIT licensed.

Contributors

danReynoldsdependabot[bot]

Issues