Documentation menu

Clients & Libraries

Desktop app

A desktop client written in Go with the Fyne toolkit. It uses the Go library underneath and keeps your API key in the operating system keychain.

Build and run

The app lives in go-gui/ (module github.com/afterdarksys/secretserver-gui, Go 1.25.7). Its go.mod points the Go library at the sibling ../go directory, so build it inside a full checkout of the clients repository.

git clone https://github.com/afterdarksys/secretserver-clients.git
cd secretserver-clients/go-gui
go build -o secretserver-gui .
./secretserver-gui

The Extractor tab imports the public github.com/straticus1/SeKretSauce/sekretsauce-cli module, which Go downloads like any other dependency. The Go client comes from the same checkout through a replace to ../go, so build inside the cloned repository.

Fyne compiles native code, so the build needs cgo (a C compiler) and the graphics development libraries for your platform.

Connect your account

Open the Settings tab and fill in:

FieldNotes
API URLDefaults to https://api.secretserver.io. Must be https; http is accepted only for localhost.
API KeySaved to the OS keychain under service com.afterdarksys.secretserver, with the API URL as the account. Leave the field empty to keep the stored key.

The URL is stored in the Fyne preferences for app ID com.afterdarksys.secretserver; the key never is. A key left in plaintext preferences by an older version is moved into the keychain on first load. If the keychain is unavailable, the app refuses to save the key rather than falling back to a file.

Read a secret

The Secrets tab lists your secrets. Select one to fetch it by name and show its fields.

Write a secret

  • New Secret: enter a name, description and data as key=value lines, one per line.
  • Edit: change the description or data. Data must keep at least one key=value pair.
  • Delete: asks for confirmation, then deletes by name.

List secrets

The Secrets tab loads the list when the client is configured. Press Refresh to reload it.

Variables tab

Assign a named variable to a credential field (name, credential type, credential UUID, field), then use Resolve template to render text such as %%LOG_SERVER_TX1_S%%. Resolved output contains secrets and stays in memory until you press Clear result.

Extractor tab

Scan System looks for unmanaged secrets in the local keychain and in files under your home directory. Keychain results include service and account names; values are left out. Select an item and use Import to SecretServer to store it as a new secret after confirmation.

Errors

Errors are shown in a dialog. Common ones:

MessageMeaning
please fill in both URL and keySettings saved with an empty field
OS keychain unavailable ...The keychain could not be read or written; nothing was stored
SecretServer client not configuredImport attempted before Settings were saved
a secret named ... already existsImport collided with an existing name
SecretServer request failed (HTTP n)API error from the Go library

Programmatic access

For scripts, use the Go library directly; the app is a thin UI over it.