Self-hosted secrets management platform — centralized secret storage, machine identities, and a CLI/SDK for injecting secrets into apps and CI.
Derived from Infisical (MIT), with a simpler developer experience and a purpose-built CLI. See NOTICE.
- Dashboard — projects, environments, secret paths, versioning, secret syncs
- Machine identities — Universal Auth (clientId/secret) plus platform attestation methods (Kubernetes, AWS, GCP, Azure, OIDC, JWT, TLS, SPIFFE, LDAP)
sanctum-cli(packages/cli) — link a repo folder to a project, pull/push/diff.envfiles, andsanctum runto inject secrets at launch. No.envneeded on disksanctum-sdk(packages/sdk) — TypeScript SDK wrapping the REST API (auth, projects, secrets, dotenv utils)
Requires Node 18+, Docker (Postgres + Redis only).
cp .env.example .env
npm install
npm run dev:db # Postgres + Redis containers
npm run dev # backend :4000 + frontend :3000Create an account at http://localhost:3000.
# build + link
cd packages/sdk && npm install && npm run build
cd ../cli && npm install && npm run build && npm link
# on a dev machine
sanctum login # interactive wizard (machine identity or token)
# in your app repo
sanctum init # link to a project or create one
sanctum agents # drop usage notes into AGENTS.md
sanctum secrets list # keys only
sanctum secrets set FOO=bar
sanctum diff .env # masked compare vs remote
sanctum pull # fetch remote -> .env
sanctum push .env --dry-run # preview changes, no writes
sanctum run -- npm run dev # inject secrets as env varssanctum-config.json is committed (project/env/path only). Credentials live in
~/.sanctum/credentials.json per profile, or SANCTUM_CLIENT_ID +
SANCTUM_CLIENT_SECRET in CI. See packages/cli for the full
command reference and packages/cli/DEMO.md for a
walkthrough.
docker compose -f docker-compose.prod.yml upOr build Dockerfile.standalone-sanctum for a single-container deployment.
MIT Expat for the community code, with two carve-outs:
ee/directories — Infisical Enterprise license (not open source; kept for upstream compatibility, disabled without a license key)packages/— MIT, written for this project