KoshKOSH

Introduction

Kosh is a local-first encrypted secret vault for developers and teams.

What is Kosh?

Kosh (Sanskrit: कोष, Koṣa, treasury) is a command-line tool that encrypts your .env secrets locally, redacts them from terminal output, and syncs them securely across your team.

Your secrets never touch disk in plaintext. When you run a command through Kosh, it injects decrypted values into the child process environment and scrubs them from all output.

How it works

kosh init               # generate user key + write config
kosh add --file .env    # encrypt secrets, store references
kosh run -- node app.js # inject + auto-redact
kosh sync --push        # share encrypted secrets with team

Install

PlatformCommand
macOS / Linuxcurl -fsSL https://kosh.useyukti.com/install.sh | sh
Homebrewbrew install VaarunSinha/kosh/kosh
Windowsirm https://kosh.useyukti.com/install.ps1 | iex
Cargocargo install kosh

See Installation for full platform instructions, build from source, and verify steps.

Architecture

ComponentPurpose
kosh-coreCrypto primitives, env parsing, vault logic
kosh-redactorOutput stream scrubbing
kosh-cliCLI interface (clap)
kosh-serverOptional team sync server

Encryption

AlgorithmRole
X25519Key exchange
XChaCha20-Poly1305Authenticated encryption (AEAD)
Argon2idKey derivation (KDF)
BLAKE3Hashing

Global flags

These flags work across all commands:

FlagShortDescription
--workspace <NAME>-wOverride the active workspace
--env <NAME>-eOverride the active environment
--jsonOutput in JSON format

Next steps

On this page