Skip to main content

An encrypted environment variable manager for developers.

Project description

NexVault

NexVault is a secure command-line tool for storing, managing, importing, exporting, and injecting environment variables using password-based encryption.

Instead of storing secrets in plaintext .env files, NexVault keeps them inside an encrypted vault protected by your password. Export them only when needed or inject them directly into your application at runtime.

Features

  • Password-protected encrypted vault
  • Securely store and retrieve environment variables
  • Store multiple key-value pairs in a single command
  • List all stored keys
  • Run applications with injected environment variables
  • Export secrets to a .env file
  • Import existing .env files into the vault
  • Export and import portable .nexvault backup files
  • Copy secret values or .env content directly to the clipboard
  • Built with modern cryptography

Installation

pip install nexvault

Quick Start

Initialize a vault

nexvault init

Check files for hardcoded secrets

nexvault check

Store a secret

nexvault set API_KEY your-secret

Store multiple secrets

nexvault setmul \
  API_KEY=your-secret \
  DATABASE_URL=postgres://localhost/db \
  DEBUG=true

Retrieve a secret

nexvault get API_KEY

Copy a secret to the clipboard

nexvault get API_KEY --copy

Remove a key

nexvault rm API_KEY 

List all stored keys

nexvault list

Run an application with injected environment variables

nexvault run python main.py

You can run any executable or command through NexVault, and all stored environment variables will be securely injected into the child process.

Examples:

nexvault run node app.js
nexvault run npm start
nexvault run cargo run

Export to a .env file

nexvault toenv

Copy .env content to the clipboard

nexvault toenv --copy

Import an existing .env file

nexvault fromenv

Export the encrypted vault

nexvault export

This creates a portable .nexvault backup that can be shared or archived.

Import a .nexvault backup

nexvault importfile backup.nexvault

Security

NexVault derives encryption keys from your password and uses authenticated encryption to protect all stored secrets.

Environment variables remain encrypted at rest and are only decrypted when explicitly requested or temporarily injected into a child process with the run command.

License

Licensed under the Apache License 2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

nexvault-1.3.0.tar.gz (15.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

nexvault-1.3.0-py3-none-any.whl (22.2 kB view details)

Uploaded Python 3

File details

Details for the file nexvault-1.3.0.tar.gz.

File metadata

  • Download URL: nexvault-1.3.0.tar.gz
  • Upload date:
  • Size: 15.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for nexvault-1.3.0.tar.gz
Algorithm Hash digest
SHA256 3d64e2f5c3dd8c59df1ead0d0fb58c0839f87cdb1f7e63fe200f1af53605ec9f
MD5 b8d86193df4091130c1e9b35a6569fa6
BLAKE2b-256 70f115453342b19f6241d73e01c591c4e577d6205d1f91c068671fdee11ae787

See more details on using hashes here.

File details

Details for the file nexvault-1.3.0-py3-none-any.whl.

File metadata

  • Download URL: nexvault-1.3.0-py3-none-any.whl
  • Upload date:
  • Size: 22.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.12.3

File hashes

Hashes for nexvault-1.3.0-py3-none-any.whl
Algorithm Hash digest
SHA256 cebb5b60d5e223c3a3278189a3ca94ea7b40df6c7c07d4c1ca95eb9b960aef4b
MD5 057c0bdaf9d95dc88ea529dd2d5ad68d
BLAKE2b-256 f7643168ad0e6e25a06c9d9351f79cc3e1b5541af736975512090695559361de

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page