Skip to main content

secretpath

secretpath resolves application secrets from a short, explicit provider path:

  1. 1Password CLI references through op read
  2. Environment variables

It is designed for CLIs and local automation that should prefer 1Password when available, fall back to environment variables when appropriate, and report where the secret came from without logging the secret itself.

secretpath never writes resolved secret values to disk. Its cache is process-local memory only.

Install

pip install secretpath

For local development:

uv sync
uv run pytest
uv run ruff check src tests

Quick Start

from secretpath import resolve_secret

result = resolve_secret(
    "Canvas API key",
    provider="auto",
    op_reference="op://Vault/Canvas/credential",
    env_var="CANVAS_API_KEY",
)

api_key = result.value
print(f"Using API key from {result.source}")

Use environment variables to avoid putting op://... references in project files:

result = resolve_secret(
    "ANTHROPIC_API_KEY",
    provider_env="MYAPP_SECRET_PROVIDER",
    op_reference_env="MYAPP_ANTHROPIC_API_KEY_OP_REFERENCE",
)

For prefix-based project conventions:

from secretpath import resolve_env_secret

result = resolve_env_secret("ANTHROPIC_API_KEY", prefix="PIPYER")

That reads:

  • PIPYER_SECRET_PROVIDER
  • PIPYER_ANTHROPIC_API_KEY_OP_REFERENCE
  • ANTHROPIC_API_KEY

For application doctor commands, reuse the same sanitized setup diagnostics as the CLI:

from secretpath import doctor_report

payload = doctor_report(check_resolution=True)

The payload reports provider availability, config files, permissions, configured secret names, optional resolution status, and issues without resolved secret values or direct op://... references.

Named Config

Local .secretpath.toml and global ~/.config/secretpath/config.toml files can store secret lookup metadata. They should contain references and environment variable names, not resolved secret values.

[defaults]
provider = "auto"

[secrets.canvas]
env_var = "CANVAS_API_KEY"
op_reference = "op://Vault/Canvas/credential"

[secrets.anthropic]
env_var = "ANTHROPIC_API_KEY"
op_reference_env = "MYAPP_ANTHROPIC_API_KEY_OP_REFERENCE"

Then:

from secretpath import resolve_named_secret

result = resolve_named_secret("canvas")

See docs/config.md for precedence and file discovery.

CLI

The CLI checks whether a secret resolves without printing the secret:

secretpath check canvas
sp check canvas
secretpath check canvas --json
secretpath list
secretpath config path
secretpath config init
secretpath config show
secretpath doctor
secretpath doctor --check
sp direnv init openai anthropic
secretpath check ANTHROPIC_API_KEY --prefix PIPYER
secretpath check API_KEY --no-config --env-var API_KEY
python -m secretpath check canvas

sp is a short alias for the secretpath command.

See docs/cli.md.

Behavior

  • provider="auto" tries 1password first, then env.
  • provider="1password" only tries op read.
  • provider="env" only reads the environment variable.
  • env_var defaults to name.
  • environment-sourced results report env:<env_var>, such as env:CANVAS_API_KEY.
  • required=False returns a SecretMiss with non-secret attempt metadata.
  • resolved values are cached in process memory by default.
  • clear_cache() clears the process-local cache.
  • clear_cache(name) clears entries for one logical secret name.

Error messages name providers tried, but intentionally avoid including op://... references, environment variable names, raw op stderr, or secret values.

Documentation

Why No Durable Secret Cache?

secretpath treats 1Password or the environment as the durable authority. A disk cache would create another secret store with weaker rotation and audit semantics. The built-in cache is intentionally limited to the current Python process.

Release files for secretpath 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secretpath 0.3.0
File Size Uploaded
secretpath-0.3.0.tar.gz 11.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secretpath 0.3.0
File Interpreter ABI Platform
secretpath-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 26.3 kB

Release files / secretpath-0.3.0.tar.gz

Download URL secretpath-0.3.0.tar.gz
Size 11.8 kB
Tags Source
SHA-256 checksum
How to use checksums
38b83ab5828f05f256387989701e9aa6ceaf2332ac7f5b35682d5ff9ec42136c
BLAKE2b-256 checksum
How to use checksums
62e39fd2f53420474e774d9ca03b5c0d77e67b5f0f6cf459313fb0d615510030
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.20 {"installer":{"name":"uv","version":"0.11.20","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / secretpath-0.3.0-py3-none-any.whl

Download URL secretpath-0.3.0-py3-none-any.whl
Size 14.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c67540df688081c4938d391f9f694582c5c499fb32c39f3362cce5596773f001
BLAKE2b-256 checksum
How to use checksums
bf14966c5623a48ddb5408a57ab6178081bbfb021da5c30c23e38467063fad53
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.20 {"installer":{"name":"uv","version":"0.11.20","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page