Installation
The SecretServer CLI (ss) is written in Go and ships as a single self-contained binary — no runtime or dependencies required.
Language
Go 1.24
Single static binary. No interpreter, no runtime, no version conflicts.
Platforms
macOS · Linux · Windows
Native binaries for amd64 and arm64 (Apple Silicon supported).
Option 1 — curl installer macOS / Linux
curl -fsSL https://secretserver.io/install | sh
Detects your OS and architecture, downloads the latest release from GitHub over HTTPS, verifies its SHA-256 against the release checksums file (and refuses to install on a mismatch), then installs to /usr/local/bin/ss if that is writable, otherwise ~/.local/bin/ss. Set SS_VERSION to pin a version or SS_INSTALL_DIR to choose the directory. The script is also at /install.sh if you want to read it first.
Option 2 — Homebrew macOS / Linux
brew install afterdarksys/tap/secretserver-cli
Installs from our official Homebrew tap. Updates automatically with brew upgrade.
Option 3 — Direct download
Download a pre-built binary from the GitHub releases page.
| Platform | Architecture | File |
|---|---|---|
| macOS | Apple Silicon (arm64) | ss_VERSION_darwin_arm64.tar.gz |
| macOS | Intel (amd64) | ss_VERSION_darwin_amd64.tar.gz |
| Linux | amd64 | ss_VERSION_linux_amd64.tar.gz |
| Linux | arm64 | ss_VERSION_linux_arm64.tar.gz |
| Windows | amd64 | ss_VERSION_windows_amd64.zip |
Option 4 — Linux packages .deb / .rpm
# Debian / Ubuntu
VERSION=1.0.0 # see the releases page
wget https://github.com/afterdarksys/secretserver-cli/releases/download/v$VERSION/ss_${VERSION}_linux_amd64.deb
sudo dpkg -i ss_${VERSION}_linux_amd64.deb
# RHEL / Fedora / Amazon Linux
wget https://github.com/afterdarksys/secretserver-cli/releases/download/v$VERSION/ss_${VERSION}_linux_amd64.rpm
sudo rpm -i ss_${VERSION}_linux_amd64.rpmConfiguration
People sign in with ss login, which opens your organization's SSO in a browser and stores a refreshing session in ~/.adkm/credentials.json. Automation (CI, servers) uses an API key from the environment or the config file instead.
ss login # browser SSO ss login --no-browser # prints a URL; paste the code shown after sign-in ss auth status
# Environment variable (recommended for CI/CD) export SS_API_KEY=sk_live_... export SS_API_URL=https://api.secretserver.io # optional, this is the default # Or write a config file mkdir -p ~/.adkm cat > ~/.adkm/config.yaml <<EOF api_key: sk_live_... api_url: https://api.secretserver.io EOF
API keys are created with POST /api/v1/api-keys by a caller holding admin:* (for example with the token from ss auth print-access-token); there is no console page for them. See the API docs. Precedence: --api-key flag > SS_API_KEY env > ss login session > ~/.adkm/config.yaml.
Verify installation
ss version # ss version 1.0.1 # commit: abc1234 # built: 2026-10-04T00:00:00Z ss secrets --help