Dworshak 🌊
dworshak is a cross-platform credential and config management solution.
There are options to manage encrypted cresentials, store plaintext config to JSON, or to leverage traditional Pythonic .env files.
dworshak is the CLI layer which allows your to edit and inspect values which you can also obtain programatically by using the wider dworshak ecosystem.
The dworshak ecosystem is build to be a configuration and credential waterfall with user-in-the-loop prompting.
Quick Start
# Install the CLI (for most environments)
pipx install "dworshak[crypto]"
# Bootstrap the security layer
dworshak setup
# Register your API credential
dworshak secret set "rjn_api" "username"
# -> You will then be prompted,
# with the input characters securely hidden.
# Alternatively, if you want to have the option to hide/show the secret value without introducing it to console history,
# use the web or gui input
dworshak prompt obtain secret "rjn_api" "password" --interface web
TL;DR: Use dworshak to securely store and retrieve secrets, configs, and env values in scripts. Enjoy the Obtain pattern.
Supports Termux, Alpine, macOS, Linux, Windows.
Clean stdout means you can assign variables directly:
PORT=$(dworshak prompt obtain config myapp port -e)
dworshak helptree
helptree is utility funtion for Typer CLIs, imported from the typer-helptree library.
- GitHub: https://github.com/City-of-Memphis-Wastewater/typer-helptree
- PyPI: https://pypi.org/project/typer-helptree/
🏗 The Ultimate Vision
To become a stable credential management tool for scripting the flow of Emerson Ovation data and related APIs, supporting multiple projects in and beyond at the Maxson Wastewater Treatment Plant.
Furthermore, we want to offer Python developers a seamless configuration management experience that they can enjoy for years to come, on all of their devices. We especially love unlocking superuser gains and rollout in Termux environments.
The Secret Sauce Behind dworshk-secret: Use Industry-standard AES (Fernet) encryption to manage a local ~/.dworshak/ directory which includes a .key file, a vault.db encrypted credential file, and a config.json file for controlling defaults.
🚀 Attributes
- Secure Vault: Fernet-encrypted SQLite storage for API credentials.
- Root of Trust: A local
.keyfile architecture that works identically on Windows and Termux. - CLI Entry: A
typer-based interface for setup and credential management.
Bash Scripting
Use dworshak to prompt for Microsoft Fabric / Azure credentials
#!/usr/bin/env bash
set -euo pipefail
# Prompt human securely
SQL_PASSWORD=$(dworshak prompt ask \
--message "Enter Fabric SQL password" \
--hide --emit)
# Push into Azure Key Vault
az keyvault secret set \
--vault-name my-fabric-vault \
--name sql-password \
--value "$SQL_PASSWORD"
echo "Secret stored in Azure Key Vault"
Use dworshak to prompt for AWS credentials
#!/usr/bin/env bash
set -euo pipefail
# 1. Human-friendly prompt
DB_PASSWORD=$(dworshak prompt ask \
--message "Enter production DB password" \
--hide --emit)
# 2. Push into AWS Secrets Manager
aws secretsmanager put-secret-value \
--secret-id prod/db/password \
--secret-string "$DB_PASSWORD"
echo "Secret stored in AWS Secrets Manager"
Recommended aliases:
alias dwobsec='dworshak prompt obtain secret'
alias dwobfig='dworshak prompt obtain config'
alias dwobenv='dworshak prompt obtain env'
Typical installation (macOS, Ubuntu, Windows 11, etc)
pipx install "dworshak[crypto]"
Termux installation
pkg install python-cryptography
pipx install dworshak --system-site-packages
iSH Alpine installation
apk add py3-cryptography
pipx install dworshak --system-site-packages
Sister Projects in the Dworshak Ecosystem
- CLI/Orchestrator: dworshak
- Interactive UI: dworshak-prompt
- Secrets Storage: dworshak-secret
- Plaintext Pathed Configs: dworshak-config
- Classic .env Injection: dworshak-env
pipx install dworshak
pip install dworshak-secret
pip install dworshak-config
pip install dworshak-env
pip install dworshak-prompt
Documentation
Metadata
Release files for dworshak 1.3.5.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dworshak-1.3.5.3.tar.gz | 9.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dworshak-1.3.5.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.0 kB
Release files / dworshak-1.3.5.3.tar.gz
| Download URL | dworshak-1.3.5.3.tar.gz |
|---|---|
| Size | 9.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
10f072a8c99714095732c5548aae50efc406d5cc0458eeb889b7733413745acc
|
|
BLAKE2b-256 checksum How to use checksums |
eae855efe48b85d53067ba81c2b62a81bbf5685336b358063ce7b867184cb780
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 16, 2026.
Transparency logRelease files / dworshak-1.3.5.3-py3-none-any.whl
| Download URL | dworshak-1.3.5.3-py3-none-any.whl |
|---|---|
| Size | 8.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f0f1a08923d3fea4d608a22e92e5b1d8fdbdb41e19915c6b465b4295c84a773f
|
|
BLAKE2b-256 checksum How to use checksums |
332d199b5240222d38ced84648041fd0f8fed5ce1b8789e840d8d0d53cd48448
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 16, 2026.
Transparency log