cofre is a tiny CLI for keeping personal secrets in GPG-encrypted files.
I use it when a secret needs to reach a shell command, but I do not want the value saved in shell history or pasted into a plain text file. It is for small personal credentials on my own machine.
OPENAI_API_KEY="$(cofre openai)" my-command- Stores secrets as
~/secrets/<name>.gpg - Uses
gpg --symmetricfor encryption - Prompts with hidden input when saving a secret
- Reads one-line secrets from stdin
- Prints only the secret value when reading
- Sends status and errors to stderr, so command substitution stays clean
- Install:
./install.sh - Save a secret:
cofre set openai - Use a secret:
OPENAI_API_KEY="$(cofre openai)" my-command - Pipe a secret in:
printf '%s\n' "$OPENAI_API_KEY" | cofre set openai - Save from the macOS clipboard:
pbpaste | cofre set openai - List saved names:
cofre ls - Remove a secret:
cofre rm openai - Use another directory:
SECRET_DIR="$HOME/private/secrets" cofre ls - Edit a multi-line secret:
cofre edit openai - Show every command:
cofre help
- If
cofre set <name>printsgpg: problem with the agent: Inappropriate ioctl for device, GPG could not open its passphrase prompt. In an interactive shell, runexport GPG_TTY="$(tty)"andgpg-connect-agent updatestartuptty /bye. If that fixes it, add theGPG_TTYexport to your shell startup file.