keycmd 🔑
Prefix any command with keycmd to source your secrets from the OS keyring, instead of risky .env files (or worse 🙈). Your credentials are exposed as environment variables for exactly one command, and nowhere else.
📖 Documentation · 📦 PyPI · 🚀 Quick Start
Supports Windows, macOS and Linux. Common applications include npm, pip, uv, poetry, docker, docker compose and kubectl.
Quick start
uv tool install keycmd
Store a credential in your OS keyring, name it in a .keycmd file:
[keys]
OPENAI_API_KEY = { credential = "my-openai-token", username = "your-username" }
...and run anything that needs it, by putting keycmd in front of the command you were going to run anyway:
keycmd python my_openai_script.py
The variable exists inside that command, and nowhere else — no .env file, no secret pasted into your terminal, nothing left behind afterwards. 😱 → 😌
Continue with the Quick Start tutorial, which walks through storing the credential on each platform.
Why keycmd?
- Your secrets stay in the keyring. The Windows Credential Manager, the macOS keychain and the Linux secret service already exist to keep credentials safe — keycmd reads from them, so a checked-out repository never has to contain a token.
- Exposed for one command only, or for a subshell with
keycmd --shellwhen you're debugging. - Configuration that follows your project, merged from your home folder, from
.keycmdfiles up the directory tree, and frompyproject.toml. - One credential, many shapes. Format strings and aliases expose the same secret as plain text, base64, or a basic auth header — whatever each tool insists on.
- Any keyring backend, through keyring, with no special configuration.
Documentation
Everything lives at korijn.github.io/keycmd:
- Installation — globally, under pyenv, or from WSL
- Running commands — prefixing a command, quoting one, subshells
- Configuration — where it lives, keys, format strings, aliases
- Keyring backends — third party backends, and keycmd's startup time
- WSL — reaching the Windows Credential Manager from a distribution
- Troubleshooting — start with
keycmd --verbose - Examples — an OpenAI API key, and one Azure DevOps token shared by poetry, npm and docker compose
- Reference — every flag, environment variable and configuration field
Contributing
Issues and pull requests are welcome. See Contributing and Testing to get set up:
uv sync
uv run pre-commit install
uv run pytest tests
License
Release files for keycmd 0.8.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| keycmd-0.8.0.tar.gz | 32.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| keycmd-0.8.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.6 kB
Release files / keycmd-0.8.0.tar.gz
| Download URL | keycmd-0.8.0.tar.gz |
|---|---|
| Size | 32.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
ea4df9ae03877dabff3f67be668cc62afb672a89a76990ad01e254d3764fc700
|
|
BLAKE2b-256 checksum How to use checksums |
958fdeb386f0c8a92af0dd6059cdabc8eae9c06e444f17a63383bd81f03ad838
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / keycmd-0.8.0-py3-none-any.whl
| Download URL | keycmd-0.8.0-py3-none-any.whl |
|---|---|
| Size | 18.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
1c647181e8c0810bf47d374c244ec1ad7fe2b51a2ea4419973aaed924aac9ca9
|
|
BLAKE2b-256 checksum How to use checksums |
ae00122c5d2e89eab01492231fd60d1d6c93d1b1896d06425e04a07cffb70f00
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|