Skip to main content

axm-vault

Catalog-resolver secrets manager (keyring + SecretStr) for AXM

CI axm-audit axm-init Coverage Python 3.12+


Overview

Catalog-resolver secrets manager (keyring + SecretStr) for AXM

Features

  • Value-less catalog — pydantic v2 models (Sensitivity, CredentialSpec, CredentialGroup) describe credential schema only; no field ever holds a secret value.
  • Entry-point discovery — load_catalog() aggregates axm.credentials groups contributed by packages (empty-safe, cached).
  • Layered resolution — Resolver walks env > file > keyring > default > prompt; the file tier is delegated to axm-config, the keyring tier is consulted only for SECRET specs.
  • Typed binding — bind(model, group) builds a pydantic model from resolved values, wrapping SECRET fields as SecretStr and returning the concrete model type.
  • Value-free doctor — doctor_data() / the vault_doctor tool report each credential's {layer, present} provenance without ever returning a secret.
  • MCP tools — vault_doctor (provenance) and vault_set (keyring/config) ship as axm.tools (MCP + CLI + DAG node).
  • Operator CLI — axm-vault exposes setup/get/set/rotate/doctor/path; interactive setup is TTY-guarded and idempotent, get masks secrets unless --reveal.
  • Frozen & strict — immutable models that forbid unknown fields (frozen=True, extra="forbid").

See the documentation for the full guide, including how to declare your package's credentials.

Installation

uv add axm-vault

Or as a workspace dependency in pyproject.toml:

[project]
dependencies = ["axm-vault"]

[tool.uv.sources]
axm-vault = { workspace = true }

Development

This package is part of the axm-forge uv workspace.

git clone https://github.com/axm-protocols/axm-forge.git
cd axm-forge
uv sync --all-groups

# Run tests for this package
uv run --package axm-vault --directory packages/axm-vault pytest -x -q

# Lint + type check + security audit + tests, all packages, from the root
make check

License

Apache-2.0 — © 2026 Gabriel Jarry

Metadata

Release files for axm-vault 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for axm-vault 0.1.0
File Size Uploaded
axm_vault-0.1.0.tar.gz 61.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for axm-vault 0.1.0
File Interpreter ABI Platform
axm_vault-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 90.1 kB

Release files / axm_vault-0.1.0.tar.gz

Download URL axm_vault-0.1.0.tar.gz
Size 61.5 kB
Tags Source
SHA-256 checksum
How to use checksums
27335fa47bd860da5c8e9c96ee37321b50cdcf92a424be0bc248272a369ae253
BLAKE2b-256 checksum
How to use checksums
a8abe15dabd9736942bcbc2604e1d63bdcb98f3b0e5c6ca05434aeb28f5fcf88
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release files / axm_vault-0.1.0-py3-none-any.whl

Download URL axm_vault-0.1.0-py3-none-any.whl
Size 28.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d5f2a821a1d6d89ad63d8036ba9c062ecaed592bd9642c89436d1e8c44a5707c
BLAKE2b-256 checksum
How to use checksums
2058cb39ea53b16f1e3d335e1d4c358fa011e7a3c9eea63d97086de9766ce726
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page