CriptEnv CLI
Zero-Knowledge secret management for developers and teams.
CriptEnv CLI is the command-line interface for the CriptEnv platform — an open-source alternative to Doppler and Infisical. Manage environment variables, API keys, and sensitive credentials with client-side AES-256-GCM encryption. Your secrets never reach our servers in plaintext.
Features
- Zero-Knowledge Encryption — Secrets are encrypted 100% client-side with AES-256-GCM before leaving your machine.
- Local Vault — SQLite-backed local cache for offline access to your secrets.
- Team Sync — Securely push and pull secrets across environments and team members.
- Audit Ready — Every operation is logged and traceable.
- CI/CD Friendly — Built-in support for CI tokens and GitHub Actions integration.
Installation
pip install criptenv
Requires Python 3.10+.
Quick Start
# Initialize the CLI
criptenv init
# Log in to your CriptEnv account
criptenv login
# Set a secret in the current environment
criptenv secrets set DATABASE_URL postgres://localhost/mydb
# List all secrets
criptenv secrets list
# Pull latest secrets from the server
criptenv sync pull
# Push local secrets to the server
criptenv sync push
Commands
| Command | Description |
|---|---|
init |
Initialize local vault and configuration |
login |
Authenticate with your CriptEnv account |
secrets set <key> <value> |
Encrypt and store a secret |
secrets get <key> |
Retrieve and decrypt a secret |
secrets list |
List all secrets in the current environment |
secrets delete <key> |
Remove a secret |
sync push |
Upload encrypted secrets to the server |
sync pull |
Download encrypted secrets from the server |
environments |
Manage project environments |
projects |
Manage projects |
doctor |
Check CLI health and connectivity |
Security
Secrets are encrypted using a key derived from your password via PBKDF2-HMAC-SHA256 (100,000 iterations) and HKDF-SHA256. The server only stores opaque encrypted blobs — it has no ability to decrypt your data.
Development
cd apps/cli
pip install -e ".[dev]"
python -m pytest tests -q
License
MIT License — see LICENSE for details.
Made with ❤️ by Jean Carlos Moreira Dias
Metadata
Release files for criptenv 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| criptenv-0.1.0.tar.gz | 36.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| criptenv-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 76.0 kB
Release files / criptenv-0.1.0.tar.gz
| Download URL | criptenv-0.1.0.tar.gz |
|---|---|
| Size | 36.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1546a2fff10661deeabe50f633e3db80b8b35676a0051fde4ba1e0661ab3d0ae
|
|
BLAKE2b-256 checksum How to use checksums |
894b00abb526491154a6f6ddb4874cf0b77399f37bdaad865e908e566e9f775a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.3
|
Release files / criptenv-0.1.0-py3-none-any.whl
| Download URL | criptenv-0.1.0-py3-none-any.whl |
|---|---|
| Size | 39.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
712897a4300bff12e431ca5fbf9213a0dd40ceba08929f7c0668364687d033b1
|
|
BLAKE2b-256 checksum How to use checksums |
41104ff9e44edff2a96ed3dfed5fcd58cb9136ae6555664f248b110a1f7b0961
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.14.3
|