KoshKOSH

The project

Kosh

Kosh (Sanskrit: कोष, Koṣa) means treasury, a place where valuables are kept. That is exactly what this tool is.

Developer secrets live in .env files, passed in plaintext, leaked in logs, and accidentally committed. Kosh fixes that. It encrypts your secrets locally using X25519 key exchange and XChaCha20-Poly1305 AEAD, stores only opaque references on disk, injects plaintext into child processes at runtime, and automatically redacts values from terminal output.

When your team needs the same secrets, Kosh syncs them through a server, encrypted end-to-end, with role-based access control. The server never sees plaintext. Neither does your terminal history.

It is local-first, offline-capable, and built in Rust. No daemon, no cloud dependency, no vendor lock-in.

License

AGPL-3.0

Language

Rust

Encryption

X25519 + XChaCha20-Poly1305

KDF

Argon2id

Read the docsView on GitHubContributing

The author

Vaarun Sinha

Vaarun Sinha

VaarunSinhanexshastra.tech ↗

Self-taught since 12. Not from curiosity alone, from an obsession with understanding how things actually work, and then making them work better.

Across Digitea, Aaj Se Code, and Upkram.ai, I kept running into the same problem: secrets scattered across machines, shared over chat, committed by accident, leaked in logs. Every project, every team, the same failure mode.

Kosh is the tool I needed. Built to handle secrets the way infrastructure should, encrypted on device, redacted from output, synced without trust assumptions. No ceremony, no cloud accounts, no exposure.

Digitea→Aaj Se Code→Upkram.ai→Nexshastra