Documentation menu

Installation

The SecretServer CLI (ss) is written in Go and ships as a single self-contained binary — no runtime or dependencies required.

Language

Go 1.24

Single static binary. No interpreter, no runtime, no version conflicts.

Platforms

macOS · Linux · Windows

Native binaries for amd64 and arm64 (Apple Silicon supported).

Option 1 — curl installer macOS / Linux

curl -fsSL https://secretserver.io/install | sh

Detects your OS and architecture, downloads the latest release from GitHub over HTTPS, verifies its SHA-256 against the release checksums file (and refuses to install on a mismatch), then installs to /usr/local/bin/ss if that is writable, otherwise ~/.local/bin/ss. Set SS_VERSION to pin a version or SS_INSTALL_DIR to choose the directory. The script is also at /install.sh if you want to read it first.

Option 2 — Homebrew macOS / Linux

brew install afterdarksys/tap/secretserver-cli

Installs from our official Homebrew tap. Updates automatically with brew upgrade.

Option 3 — Direct download

Download a pre-built binary from the GitHub releases page.

PlatformArchitectureFile
macOSApple Silicon (arm64)ss_VERSION_darwin_arm64.tar.gz
macOSIntel (amd64)ss_VERSION_darwin_amd64.tar.gz
Linuxamd64ss_VERSION_linux_amd64.tar.gz
Linuxarm64ss_VERSION_linux_arm64.tar.gz
Windowsamd64ss_VERSION_windows_amd64.zip

Option 4 — Linux packages .deb / .rpm

# Debian / Ubuntu
VERSION=1.0.0   # see the releases page
wget https://github.com/afterdarksys/secretserver-cli/releases/download/v$VERSION/ss_${VERSION}_linux_amd64.deb
sudo dpkg -i ss_${VERSION}_linux_amd64.deb

# RHEL / Fedora / Amazon Linux
wget https://github.com/afterdarksys/secretserver-cli/releases/download/v$VERSION/ss_${VERSION}_linux_amd64.rpm
sudo rpm -i ss_${VERSION}_linux_amd64.rpm

Configuration

People sign in with ss login, which opens your organization's SSO in a browser and stores a refreshing session in ~/.adkm/credentials.json. Automation (CI, servers) uses an API key from the environment or the config file instead.

ss login              # browser SSO
ss login --no-browser # prints a URL; paste the code shown after sign-in
ss auth status
# Environment variable (recommended for CI/CD)
export SS_API_KEY=sk_live_...
export SS_API_URL=https://api.secretserver.io   # optional, this is the default

# Or write a config file
mkdir -p ~/.adkm
cat > ~/.adkm/config.yaml <<EOF
api_key: sk_live_...
api_url: https://api.secretserver.io
EOF

API keys are created with POST /api/v1/api-keys by a caller holding admin:* (for example with the token from ss auth print-access-token); there is no console page for them. See the API docs. Precedence: --api-key flag > SS_API_KEY env > ss login session > ~/.adkm/config.yaml.

Verify installation

ss version
# ss version 1.0.1
#   commit: abc1234
#   built: 2026-10-04T00:00:00Z

ss secrets --help