KoshKOSH
Kosh vault icon

KOSH

कोष, a treasury

Encrypt your secrets locally. Redact them from terminal output. Sync securely with your team.

macOS / Linux
curl -fsSL https://kosh.useyukti.com/install.sh | sh
Homebrew
brew install VaarunSinha/kosh/kosh
Windows (PowerShell)
irm https://kosh.useyukti.com/install.ps1 | iex
Cargo
cargo install kosh

All installation methods →

Read the docsGitHub

What it does

Built for secrets that matter.

▣

Encrypted at rest

X25519 + XChaCha20-Poly1305 AEAD. Your secrets never touch disk in plaintext.

◎

Automatic redaction

kosh run intercepts stdout and stderr, scrubbing secret values before they reach your terminal.

⊕

Team-ready

Sync encrypted secrets across your team. Role-based access: owner, admin, developer, readonly, ci.

◈

Local-first

Works fully offline. The server is optional, use it only when you need team sync.

How it works

Four commands from zero to secure.

01
kosh init

Generate your user key and write the default config. One time, per machine.

Docs →
02
kosh add --file .env

Encrypt every plain value in your .env file. References replace the originals.

Docs →
03
kosh run -- node server.js

Inject decrypted secrets into the child process. Output is automatically redacted.

Docs →
04
kosh sync --push

Push encrypted secrets to the server when your team needs access.

Docs →
View all commands →

Privacy & Security

Cryptography you can audit.

Kosh uses established, audited primitives from the Rust dalek, chacha20poly1305, and argon2 crates. No custom crypto. No telemetry. No cloud accounts required.

Key exchangeX25519

Elliptic-curve Diffie-Hellman over Curve25519. Each team member's public key is used to derive a shared secret, no key material is ever transmitted.

EncryptionXChaCha20-Poly1305

Authenticated encryption with associated data (AEAD). Provides both confidentiality and integrity. Nonces are 192-bit, making collisions computationally impossible.

Key derivationArgon2id

Memory-hard KDF designed to resist GPU and ASIC brute-force attacks. Used to derive the local encryption key from your passphrase.

HashingBLAKE3

Fast, secure cryptographic hash function used for content-addressed secret references.

Key storageOS keychain

Your private key is stored in the operating-system keychain (macOS Keychain, Windows Credential Manager, or Linux libsecret). Kosh never writes plaintext keys to disk.

On-device onlyZero server trust

Decryption happens exclusively on your machine. The sync server stores only ciphertext and never receives your private key or any plaintext value.

⊛

On-device decryption, always. Your private key never leaves your machine. The Kosh server (if used) stores only encrypted blobs. Even if the server is compromised, your secrets remain ciphertext without your local key.