Vaultscribe
Vaultscribe is a tool for managing secrets. It's intended for solo devs and small teams. It uses Google Cloud Secret Manager to store secrets, and can sync secrets to multiple targets (GCloud Run, Cloudflare Pages, Github Actions, etc). It also generates code so you can access the secrets in your apps.
GCloud Secret Manager offers 6 secrets for free. Vaultscribe bundles up all your secrets, and stores them in a single 'secret slot' - meaning you can practically store as many * secrets as you like.
Installation
uv add --dev vaultscribe
or
pip install vaultscribe
Quickstart
Prerequisites:
- Google Cloud SDK CLI installed, with Secret Manager set up (see below).
Quick Usage
# Scaffold a new project. This will create a vaultscribe.toml file.
vs init
# Start a time-limited authenticated session - best practice for not leaving an active gcloud session running
vs shell
# Fetch secrets from GCloud Secret Manager for 'prod' environment, store in '.secrets.prod' file. Unset secrets are left blank.
vs pull prod
# Push secrets from '.secrets.prod' to GCloud Secret Manager for 'prod' environment. Also generates code and syncs secrets to deploy targets.
vs push prod
# Fetch secrets from GCloud Secret Manager and display
vs show prod
Vaultscribe Concepts
More details here.
Vaultscribe Commands
More details here.
GCloud Secrets Manager first time setup
# Enable Secret Manager for your project
gcloud services enable secretmanager.googleapis.com --project=YOUR_PROJECT_ID
GCloud Secret Manager Quotas
Each secret 'slot' in GCloud Secret Manager has a 64KiB size limit. See here. So while, to paraphrase, "64KiB ought to be enough for anybody", you may hit this limit if you have a very large number of secrets, or if you store really big secrets. If you hit the limit, you probably need a more 'enterprise-y' secrets manager.
Release files for vaultscribe 0.13.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vaultscribe-0.13.0.tar.gz | 155.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vaultscribe-0.13.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 227.6 kB
Release files / vaultscribe-0.13.0.tar.gz
| Download URL | vaultscribe-0.13.0.tar.gz |
|---|---|
| Size | 155.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
935bb02055a6a272427e65285036a13adcdd7c5ebbb25774715267fe9d52414f
|
|
BLAKE2b-256 checksum How to use checksums |
577c76ca81ef97602a08daf3162c50badcdfb974b2b43f3f0157b5f953086e35
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 20, 2026.
Transparency logRelease files / vaultscribe-0.13.0-py3-none-any.whl
| Download URL | vaultscribe-0.13.0-py3-none-any.whl |
|---|---|
| Size | 72.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
65dfd785c8044c2561b95e7d95ee50a8d7e73645c23fbd4d51be69bd23b4bf5d
|
|
BLAKE2b-256 checksum How to use checksums |
8bac4a8ff0ec62ded33c2fe2bf18b6918d9ae8afdc4ba51443295aa48061c8a7
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on May 20, 2026.
Transparency log