Skip to main content

navig-vault

A free, standalone, encrypted developer secrets manager — Doppler / 1Password-CLI / Infisical / Bitwarden class — that installs without navig and shares one vault.

Status: the library layer is real; the engine is still being extracted.

0.2.0 ships working code, not a skeleton — the vault's types, SecretStr, TOTP, and the path seam that makes a standalone install read the same ~/.navig/vault navig uses:

from navig_vault import SecretStr, Credential, CredentialType, totp_now, vault_dir

s = SecretStr("hunter2")
print(s)          # masked in reprs, logs and tracebacks

These are not a copy. navig.vault.types and friends inside navig are now shims that alias themselves to this package (sys.modules[__name__] = _impl), so there is exactly one source of truth and the two cannot drift — a guard in navig's suite asserts the module objects are identical.

Still in navig for now: the encryption engine (crypto, storage, resolver, sessions) and the commands. So there is deliberately no nv binary yet — claiming a two-letter global command for something that does nothing is not a decision to undo later. Use navig vault add|get|list until the engine lands here.

What it will be

  • Install-without-navig: pip install navig-vaultnavig-vault (alias nv) works on its own. Add navig later and they share the same encrypted vault automatically.
  • Runtime injection: navig-vault run -- <cmd> injects real secret values from the encrypted vault into a process's environment at runtime (no plaintext .env on disk).
  • Secret types: API keys, logins, cards, passport, TOTP.
  • Frictionless unlock: OS keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service) with a passphrase fallback.
  • Apache-2.0, own subdomain vault.navig.run.

Layout

navig-vault/
  pyproject.toml        # name "navig-vault", scripts: navig-vault + nv
  LICENSE               # Apache-2.0
  README.md
  navig_vault/
    __init__.py         # package metadata
    cli.py              # `navig-vault` / `nv` entrypoint  (stub)
    __main__.py         # `python -m navig_vault`
  tests/
    test_smoke.py

Develop

cd navig-vault
python -m pip install -e ".[dev]"
navig-vault --help      # or:  nv --help   or:  python -m navig_vault
pytest -q

Relationship to navig

Inside navig it remains navig vault. navig-vault owns the code; navig-core re-exports it, so the two never fork. See the implementation plan (extract-from-navig-core, share-don't-fork) in the project's Claude plans (i-ant-to-make-staged-prism).

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

navig_vault-0.2.0.tar.gz (22.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

navig_vault-0.2.0-py3-none-any.whl (19.2 kB view details)

Uploaded Python 3

Release history Release notifications | RSS feed

This release

0.2.0 This release

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page