Skip to main content

An encrypted environment variable manager for developers.

Project description

NexVault

NexVault is a secure command-line tool for storing, managing, importing, exporting, and injecting environment variables using password-based encryption.

Instead of storing secrets in plaintext .env files, NexVault keeps them inside an encrypted vault protected by your password. Export them only when needed or inject them directly into your application at runtime.

Features

  • Password-protected encrypted vault
  • Securely store and retrieve environment variables
  • Store multiple key-value pairs in a single command
  • List all stored keys
  • Run applications with injected environment variables
  • Export secrets to a .env file
  • Import existing .env files into the vault
  • Export and import portable .nexvault backup files
  • Copy secret values or .env content directly to the clipboard
  • Built with modern cryptography

Installation

pip install nexvault

Quick Start

Initialize a vault

nexvault init

Check files for hardcoded secrets

nexvault check

Store a secret

nexvault set API_KEY your-secret

Store multiple secrets

nexvault setmul \
  API_KEY=your-secret \
  DATABASE_URL=postgres://localhost/db \
  DEBUG=true

Retrieve a secret

nexvault get API_KEY

Copy a secret to the clipboard

nexvault get API_KEY --copy

Remove a key

nexvault remove API_KEY 

Remove multiple key

nexvault removemul API_KEY API_KEY_2 API_KEY_3

List all stored keys

nexvault list

Run an application with injected environment variables

nexvault run python main.py

You can run any executable or command through NexVault, and all stored environment variables will be securely injected into the child process.

Examples:

nexvault run node app.js
nexvault run npm start
nexvault run cargo run

Export to a .env file

nexvault toenv

Copy .env content to the clipboard

nexvault toenv --copy

Import an existing .env file

nexvault fromenv

Export the encrypted vault

nexvault export

This creates a portable .nexvault backup that can be shared or archived.

Import a .nexvault backup

nexvault importfile backup.nexvault

Security

NexVault derives encryption keys from your password and uses authenticated encryption to protect all stored secrets.

Environment variables remain encrypted at rest and are only decrypted when explicitly requested or temporarily injected into a child process with the run command.

License

Licensed under the Apache License 2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

nexvault-1.4.1.tar.gz (16.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

nexvault-1.4.1-py3-none-any.whl (22.4 kB view details)

Uploaded Python 3

File details

Details for the file nexvault-1.4.1.tar.gz.

File metadata

  • Download URL: nexvault-1.4.1.tar.gz
  • Upload date:
  • Size: 16.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for nexvault-1.4.1.tar.gz
Algorithm Hash digest
SHA256 579d00682bd3bf17ca770be77587328445596d8254ed5636e78f3d3ad13da177
MD5 d7637660c118ea54048aa28c8619e5e1
BLAKE2b-256 5b31a79291aff19a8f6f608d118e14a91d499549552888a5e88f859660542973

See more details on using hashes here.

File details

Details for the file nexvault-1.4.1-py3-none-any.whl.

File metadata

  • Download URL: nexvault-1.4.1-py3-none-any.whl
  • Upload date:
  • Size: 22.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for nexvault-1.4.1-py3-none-any.whl
Algorithm Hash digest
SHA256 93bdfeeba11e7dad9aff13ef2a73baf164b08107eda2487f21cf44738d92da4f
MD5 fa7d3a79a255dc4a185fa9f70ad3a86c
BLAKE2b-256 b0bd499daaf1419fa5841b4445228cb61ad5dbcd18e2a07115624c51caf22a55

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page