Clients & Libraries
Desktop app
A desktop client written in Go with the Fyne toolkit. It uses the Go library underneath and keeps your API key in the operating system keychain.
Build and run
The app lives in go-gui/ (module github.com/afterdarksys/secretserver-gui, Go 1.25.7). Its go.mod points the Go library at the sibling ../go directory, so build it inside a full checkout of the clients repository.
git clone https://github.com/afterdarksys/secretserver-clients.git cd secretserver-clients/go-gui go build -o secretserver-gui . ./secretserver-gui
The Extractor tab imports the public github.com/straticus1/SeKretSauce/sekretsauce-cli module, which Go downloads like any other dependency. The Go client comes from the same checkout through a replace to ../go, so build inside the cloned repository.
Fyne compiles native code, so the build needs cgo (a C compiler) and the graphics development libraries for your platform.
Connect your account
Open the Settings tab and fill in:
| Field | Notes |
|---|---|
| API URL | Defaults to https://api.secretserver.io. Must be https; http is accepted only for localhost. |
| API Key | Saved to the OS keychain under service com.afterdarksys.secretserver, with the API URL as the account. Leave the field empty to keep the stored key. |
The URL is stored in the Fyne preferences for app ID com.afterdarksys.secretserver; the key never is. A key left in plaintext preferences by an older version is moved into the keychain on first load. If the keychain is unavailable, the app refuses to save the key rather than falling back to a file.
Read a secret
The Secrets tab lists your secrets. Select one to fetch it by name and show its fields.
Write a secret
- New Secret: enter a name, description and data as
key=valuelines, one per line. - Edit: change the description or data. Data must keep at least one
key=valuepair. - Delete: asks for confirmation, then deletes by name.
List secrets
The Secrets tab loads the list when the client is configured. Press Refresh to reload it.
Variables tab
Assign a named variable to a credential field (name, credential type, credential UUID, field), then use Resolve template to render text such as %%LOG_SERVER_TX1_S%%. Resolved output contains secrets and stays in memory until you press Clear result.
Extractor tab
Scan System looks for unmanaged secrets in the local keychain and in files under your home directory. Keychain results include service and account names; values are left out. Select an item and use Import to SecretServer to store it as a new secret after confirmation.
Errors
Errors are shown in a dialog. Common ones:
| Message | Meaning |
|---|---|
| please fill in both URL and key | Settings saved with an empty field |
| OS keychain unavailable ... | The keychain could not be read or written; nothing was stored |
| SecretServer client not configured | Import attempted before Settings were saved |
| a secret named ... already exists | Import collided with an existing name |
| SecretServer request failed (HTTP n) | API error from the Go library |
Programmatic access
For scripts, use the Go library directly; the app is a thin UI over it.