vinibrsl/cofre

Tiny CLI for keeping personal secrets in GPG-encrypted files

★ 1Forks 0ShellGitHub ↗Compare

README

cofre

cofre is a tiny CLI for keeping personal secrets in GPG-encrypted files.

I use it when a secret needs to reach a shell command, but I do not want the value saved in shell history or pasted into a plain text file. It is for small personal credentials on my own machine.

OPENAI_API_KEY="$(cofre openai)" my-command

What It Does

  • Stores secrets as ~/secrets/<name>.gpg
  • Uses gpg --symmetric for encryption
  • Prompts with hidden input when saving a secret
  • Reads one-line secrets from stdin
  • Prints only the secret value when reading
  • Sends status and errors to stderr, so command substitution stays clean

Quick Usage

  • Install: ./install.sh
  • Save a secret: cofre set openai
  • Use a secret: OPENAI_API_KEY="$(cofre openai)" my-command
  • Pipe a secret in: printf '%s\n' "$OPENAI_API_KEY" | cofre set openai
  • Save from the macOS clipboard: pbpaste | cofre set openai
  • List saved names: cofre ls
  • Remove a secret: cofre rm openai
  • Use another directory: SECRET_DIR="$HOME/private/secrets" cofre ls
  • Edit a multi-line secret: cofre edit openai
  • Show every command: cofre help

Troubleshooting

  • If cofre set <name> prints gpg: problem with the agent: Inappropriate ioctl for device, GPG could not open its passphrase prompt. In an interactive shell, run export GPG_TTY="$(tty)" and gpg-connect-agent updatestartuptty /bye. If that fixes it, add the GPG_TTY export to your shell startup file.

Contributors

vinibrsl

Issues