Software
Clients & libraries
Everything you need to use SecretServer from code, playbooks, a desktop and AI coding tools, in one repository.
What it is
| Component | What it does |
|---|---|
| Go, Python, Node.js, PHP | Libraries over the REST API: path-based reads, secret CRUD, certificates, keys, credentials, named variables, plus a generic call for any route |
| Ansible lookup | Reads secrets and resolves %%NAME%% templates inside playbooks |
| Desktop app | A Fyne GUI for secrets and variables that stores your API key in the OS keychain |
| MCP bridge | Lets MCP clients sign with non-exportable HSM and smart-card keys, and optionally resolve allowlisted variables |
| Agent skills | Guidance packages for Codex and Claude Code that enforce a least-privilege workflow |
| Offline cache service | A reviewed design for an encrypted offline lease cache; not yet a running daemon |
Who it is for
- Developers reading configuration and credentials at runtime instead of baking them into images or env files.
- Automation engineers using Ansible or scripts that need scoped, audited access.
- Teams letting coding agents sign releases or read a few named values without handing them raw keys.
How it works
Every client authenticates with a scoped API key sent as a bearer token to /api/v1. The libraries share one set of rules:
- https only, with plain http allowed just for loopback hosts. TLS verification cannot be disabled.
- Redirects are never followed, so the key cannot be replayed to another origin.
- Errors report the HTTP status without echoing response bodies.
- Partial secret updates are refused unless you opt in or pass an ETag, so an older server cannot blank fields.
- Mutations are not retried automatically.
Install
The repository is public under the MIT license. The libraries are not published to PyPI, npm or Packagist, so install them from the repository. The secretserver name on PyPI belongs to an unrelated package; do not pip install secretserver.
git clone https://github.com/afterdarksys/secretserver-clients.git cd secretserver-clients pip install ./python # Python (cd node && npm install && npm run build) # Node.js, then: npm install ./node composer config repositories.secretserver path ./php # PHP (run in your project with the real path) go get github.com/afterdarksys/secretserver-clients/go@latest # Go (run in your module) (cd mcp && go build -o secretserver-mcp .) # MCP bridge
Each language has a full walkthrough under Clients & Libraries in the docs.
Platform support
| Client | Requires |
|---|---|
| Python | Python 3.8+, standard library only |
| Node.js / TypeScript | Node.js 18+ (native fetch), ESM |
| PHP | PHP 8.0+ with curl and json |
| Go | Go 1.22+ |
| Ansible lookup | Ansible with Python urllib; the collection is tested on Ansible Core 2.21 |
| Desktop app | Go 1.25.7+, cgo and platform graphics libraries (Fyne), an OS keychain |
| MCP bridge | Go 1.25+ |