An SSH agent
vallkey ssh-agent signs with the Ed25519 and ECDSA P-256 keys in your vault, speaking OpenSSH's own agent protocol, so ssh and git use it as they are. With --confirm, it asks before each signature.
Command line, SSH agent and secrets
The vallkey command gives scripts, shells and CI what's in your vault, so a password or an API key lives in Vallkey and not in a .env file, a shell history or a CI setting.
$ eval "$(vallkey unlock)"
$ export DB_PASSWORD=vallkey://Work/Database/password
$ vallkey run -- ./migrate
$ vallkey inject -i config.yml.tpl -o config.yml
$ vallkey ssh-agent
SSH_AUTH_SOCK=…/com.vallkey.cli/ssh-agent.sock
How it works
vallkey login adds the computer as a device of its own. vallkey unlock starts a session for that shell, which ends after 30 minutes unused.
A reference such as vallkey://Work/Database/password names a vault, an item and a field. It's safe to commit: it holds no secret.
vallkey run starts a command with the references in its environment replaced by what they name. vallkey inject fills a config file's template the same way.
The details
vallkey ssh-agent signs with the Ed25519 and ECDSA P-256 keys in your vault, speaking OpenSSH's own agent protocol, so ssh and git use it as they are. With --confirm, it asks before each signature.
An account of its own for a script or a build, with its own keys, that opens only the vaults you share with it. Its token goes in your CI's secrets; nobody's master password does. Delete it to take everything back at once.
Each shell has its own session, kept going by use and ended by vallkey lock. A command started with vallkey run gets the secrets it names, and never the session.
Reading an item from an organization's vault goes in its audit log, as opening it in an app does. Items shared as fill-only are refused: their secrets are never shown, by the command line either.
The SSH agent runs on macOS and Linux, and leaves RSA keys out. vallkey run doesn't mask secrets in what its command prints. It keeps one account on a computer, and saves new logins only: other kinds of item are made in the apps.
Availability
As a signed download for macOS, Linux and Windows, or with Homebrew.
Everything the service account logs in with, so treat it as a secret. It starts with vlk_sa_, so secret scanners can catch one that leaks.
Yes. The terminal shows the page to open and the code that page should show, as the apps do.
Vallkey opens soon. Join the waitlist to hear first.