The project
Kosh
Kosh (Sanskrit: कोष, Koṣa) means treasury, a place where valuables are kept. That is exactly what this tool is.
Developer secrets live in .env files, passed in plaintext, leaked in logs, and accidentally committed. Kosh fixes that. It encrypts your secrets locally using X25519 key exchange and XChaCha20-Poly1305 AEAD, stores only opaque references on disk, injects plaintext into child processes at runtime, and automatically redacts values from terminal output.
When your team needs the same secrets, Kosh syncs them through a server, encrypted end-to-end, with role-based access control. The server never sees plaintext. Neither does your terminal history.
It is local-first, offline-capable, and built in Rust. No daemon, no cloud dependency, no vendor lock-in.
License
AGPL-3.0
Language
Rust
Encryption
X25519 + XChaCha20-Poly1305
KDF
Argon2id
The author
Vaarun Sinha
Self-taught since 12. Not from curiosity alone, from an obsession with understanding how things actually work, and then making them work better.
Across Digitea, Aaj Se Code, and Upkram.ai, I kept running into the same problem: secrets scattered across machines, shared over chat, committed by accident, leaked in logs. Every project, every team, the same failure mode.
Kosh is the tool I needed. Built to handle secrets the way infrastructure should, encrypted on device, redacted from output, synced without trust assumptions. No ceremony, no cloud accounts, no exposure.
