Documentation menu

Software

Clients & libraries

Everything you need to use SecretServer from code, playbooks, a desktop and AI coding tools, in one repository.

What it is

ComponentWhat it does
Go, Python, Node.js, PHPLibraries over the REST API: path-based reads, secret CRUD, certificates, keys, credentials, named variables, plus a generic call for any route
Ansible lookupReads secrets and resolves %%NAME%% templates inside playbooks
Desktop appA Fyne GUI for secrets and variables that stores your API key in the OS keychain
MCP bridgeLets MCP clients sign with non-exportable HSM and smart-card keys, and optionally resolve allowlisted variables
Agent skillsGuidance packages for Codex and Claude Code that enforce a least-privilege workflow
Offline cache serviceA reviewed design for an encrypted offline lease cache; not yet a running daemon

Who it is for

  • Developers reading configuration and credentials at runtime instead of baking them into images or env files.
  • Automation engineers using Ansible or scripts that need scoped, audited access.
  • Teams letting coding agents sign releases or read a few named values without handing them raw keys.

How it works

Every client authenticates with a scoped API key sent as a bearer token to /api/v1. The libraries share one set of rules:

  • https only, with plain http allowed just for loopback hosts. TLS verification cannot be disabled.
  • Redirects are never followed, so the key cannot be replayed to another origin.
  • Errors report the HTTP status without echoing response bodies.
  • Partial secret updates are refused unless you opt in or pass an ETag, so an older server cannot blank fields.
  • Mutations are not retried automatically.

Install

The repository is public under the MIT license. The libraries are not published to PyPI, npm or Packagist, so install them from the repository. The secretserver name on PyPI belongs to an unrelated package; do not pip install secretserver.

git clone https://github.com/afterdarksys/secretserver-clients.git
cd secretserver-clients

pip install ./python                                   # Python
(cd node && npm install && npm run build)              # Node.js, then: npm install ./node
composer config repositories.secretserver path ./php   # PHP (run in your project with the real path)
go get github.com/afterdarksys/secretserver-clients/go@latest   # Go (run in your module)
(cd mcp && go build -o secretserver-mcp .)             # MCP bridge

Each language has a full walkthrough under Clients & Libraries in the docs.

Platform support

ClientRequires
PythonPython 3.8+, standard library only
Node.js / TypeScriptNode.js 18+ (native fetch), ESM
PHPPHP 8.0+ with curl and json
GoGo 1.22+
Ansible lookupAnsible with Python urllib; the collection is tested on Ansible Core 2.21
Desktop appGo 1.25.7+, cgo and platform graphics libraries (Fyne), an OS keychain
MCP bridgeGo 1.25+