Varlatch

Secrets management for the agentic era

No more secrets in .env files.

Get started

How it works

Your agent does the work. You keep the keys.

  1. Set it up once

    varlatch init

    varlatch init adds the Varlatch skill, so your agent knows not to read .env files or put secrets in commands.

  2. Ask in plain words

    Move our .env into Varlatch.

    Your agent imports the file without printing a value, deletes it, and runs your app with its output masked.

  3. The secret parts stay yours

    $ varlatch values set STRIPE_KEY -e production
    Value for STRIPE_KEY (input hidden):

    Signing in comes back to you as an address and a code to approve with your passkey. Entering a provider’s key or showing a secret comes back as a command for your own terminal, and a change waits for your yes.

The CLI recognises Claude Code, Codex, Cursor, Copilot, Gemini CLI, and OpenCode sessions, and every step is a plain command you can run yourself. Which agents were evaluated.

Two ways to work

Masked by default, placeholders when it needs a key.

Assisted mode

varlatch --assisted

Use it forEveryday work in your repo: moving .env files in, running tests and the dev server, checking a deploy.

You approve
Keyling runs the CLI
Your app gets the values
What Keyling seescharging with [REDACTED:STRIPE_KEY]

Secrets are masked in the output, a secret on the command line is refused, and the secret steps come back to you. It protects against accidents; your approvals are the control.

Agent-safe run

varlatch run --agent-safe

Use it forAn agent that calls an API itself, like Stripe’s, and should not hold the real key. Other secrets, like a database URL, stay out of the run.

Keyling holds a placeholder
The Broker adds the real key
Only hosts you allow get it
What Keyling seesSTRIPE_KEY=vlch_ph_v1_9f2c41e8…

You launch the agent as its own identity. The key goes only into the header or field you name, and a key echoed back is scrubbed from the response.

For MCP hosts without a shell, varlatch mcp ships inside the CLI: configuration metadata, the active Contract, validation, and audit events. No tool returns or writes a secret’s value.

A day with Varlatch

Nine ways secrets leak, and what your agent does instead.

ProblemTodayWith Varlatch

Secrets spread across every machine.

Every machine keeps .env files: copied from chat, backed up, sometimes committed.

varlatch import moves them in without printing a value; varlatch run hands values to your app’s process only.

Onboarding means sending secrets around.

A new teammate gets the .env in a chat message, and keeps it after they leave.

Invite them instead: a passkey, and a grant for exactly the environments they need.

The agent needs a key.

You paste a key into the agent chat. Now it is in the context, the logs, and the history.

Your agent hands you a command for your own terminal, which asks for the key without showing it.

Agents read everything they can reach.

An agent with a shell can cat .env and read your production key.

Launched agent-safe, it holds placeholders. The Broker adds the real key only for hosts you allow.

Broken config is found in production.

A missing or malformed value passes review and crashes production on boot.

A typed Contract: generated types in your code, and varlatch validate fails CI first.

Rotating a key: five dashboards and an outage.

Rotating a key means five dashboards, and an outage when you miss one.

Rotate once with a grace period; Varlatch pushes the new key to Coolify, GitHub Actions, and Convex.

One breach exposes everything.

Compromise the database or the dashboard and every secret goes with it.

Only varlatchd decrypts, and its root key is not in the database.

Nobody can say who used what.

When a key leaks, nobody can say who had it.

Every use, reveal, and denial is recorded in an append-only audit log.

Self-hosting sounds like a lost weekend.

Self-hosting means TLS, keys, untested backups, and scary upgrades.

varlatch setup takes a fresh host to a running installation; backups are encrypted and verified.

Think you’ve got it? Find the nine yourself: walk around with Keyling, look at anything odd, and decide what your agent may do.

FAQ

Can my coding agent see my secrets?

Not on the documented flow. In assisted mode the CLI never prints a secret value, refuses one on the command line, and masks secrets in the output of the commands it runs. Launched agent-safe, the agent holds placeholders only. Assisted mode protects against accidents: your agent runs as you, so your approvals are what stop deliberate misuse.

What does the agent do when it needs a key?

It stops and hands you a command for your own terminal, such as varlatch values set STRIPE_KEY -e production, which asks for the value without showing it. A value Varlatch can create, like a session key, the agent can generate with --generate after you approve; nobody sees it.

Which coding agents does it work with?

The instructions are plain text in the open Agent Skills format and AGENTS.md, with shell commands and no agent-specific tools. The CLI recognises Claude Code, Codex, Cursor, Copilot, Gemini CLI, and OpenCode sessions and turns assisted mode on by itself. In a dated baseline evaluation (October 2026, Varlatch 0.14.3), the command-line coding agents Claude Code 2.1.278 with Claude Sonnet 5.5 and Codex CLI 0.160.1 passed all 40 cases, 20 each, with no hooks, against a local test server (what was evaluated). Other coding agents, other versions, and editor or cloud interfaces have not been evaluated.

Can I use it without an agent?

Yes. Everything your agent does is a plain varlatch command or a click in the dashboard. The agent only saves you the typing.

Do I need MCP?

Only for an MCP host that gives its model no shell. A coding agent with a shell uses the CLI directly, in assisted mode. varlatch mcp ships inside the CLI for the others.

Is Varlatch open source?

Varlatch's own code is. The server and dashboard are AGPL-3.0, and the CLI and SDKs are Apache-2.0 (license). By default Varlatch runs on the Convex backend, which is source-available, not open source: its license, FSL-1.1-Apache-2.0, permits internal use, which includes running Varlatch for your own organization, and each version becomes Apache-2.0 two years after its release.

Hosted backup

Off-site backups, without a bucket of your own.

Varlatch is free to self-host. Next is an optional hosted off-site backup: your server encrypts every backup before it leaves, with a key we never see.

  • One email when the hosted backup opens
  • Early builds, only if you ask for them
  • Your address is never shared
Which coding agents do you use? optional
Also email me about optional

We send a link to confirm your address first. We only email you about Varlatch; unsubscribe any time. Privacy