# undisclosed

> Command line tool to handle encrypted secrets

Latest version **2.3.3** (published 2026-06-16) · GPL-3.0-or-later license · 0 weekly downloads

## Install

```sh
npm install undisclosed
pnpm add undisclosed
yarn add undisclosed
bun add undisclosed
```

Provides the command `undisclosed`.

## Health

**Score 60/100 (C)** — status: active.

Positive: has types; no vulnerabilities; recently updated; high quality score.

Warnings: low downloads; no esm support.

## Facts

| | |
|---|---|
| Version | 2.3.3 |
| Published | 2026-06-16 |
| First published | 2022-12-06 |
| Weekly downloads | 0 |
| License | GPL-3.0-or-later |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 1 |
| Unpacked size | 115.4 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Miguel Ángel Sánchez Chordi |
| Maintainers | mangelsnc |

## Links

- npm: https://www.npmjs.com/package/undisclosed
- npm.io page: https://npm.io/package/undisclosed

## Dependencies (1)

- [rimraf](https://npm.io/package/rimraf.md) ^3.0.2

## Recent versions

- 2.3.3 (latest) — 2026-06-16
- 2.2.0 — 2023-01-05
- 2.1.0 — 2023-01-04
- 2.0.0 — 2023-01-04
- 1.2.0 — 2023-01-02
- 1.1.0 — 2022-12-06
- 1.0.0 — 2022-12-06

## README

# :speak_no_evil: undisclosed

Simple CLI tool to handle encrypted secrets, heavily inspired in [Symfony Secrets](https://symfony.com/doc/current/configuration/secrets.html).

With `undisclosed` you can set and store your credentials encrypted, and dump it in plain whenever you want.

## init
Execute `undisclosed init` to create a default config file template and the folder to store the keys.

## generate-keypair
With `undisclosed generate-keypair` you will generate your keypair. It will be used to encrypt all your data.

**:warning: CAUTION:** Never commit your private key files to a version control system.

```
$ undisclosed generate-keypair
┌─────────┬───────────┬────────────────────────────────────────────┬───────────────────────────┐
│ (index) │   type    │                    path                    │           value           │
├─────────┼───────────┼────────────────────────────────────────────┼───────────────────────────┤
│    0    │ 'public'  │ '/Users/mangel/Workspace/test/public.pem'  │ '-----BEGIN RSA PUBLI...' │
│    1    │ 'private' │ '/Users/mangel/Workspace/test/private.pem' │ '-----BEGIN RSA PRIVA...' │
└─────────┴───────────┴────────────────────────────────────────────┴───────────────────────────┘
```

## list
With `undisclosed list` you can list the secrets you previously stored.

```
$ undisclosed list
┌─────────┬────────┬───────────────────────────┐
│ (index) │  key   │           value           │
├─────────┼────────┼───────────────────────────┤
│    0    │ 'USER' │ 'XdnN70UTz1adJZIVUcb1...' │
└─────────┴────────┴───────────────────────────┘
```

## set
With `undisclosed set KEY value` you can store a new secret or update an existing one.

```
$ undisclosed set USER root
┌─────────┬────────┬───────────────────────────┐
│ (index) │  key   │           value           │
├─────────┼────────┼───────────────────────────┤
│    0    │ 'USER' │ 'XdnN70UTz1adJZIVUcb1...' │
└─────────┴────────┴───────────────────────────┘
```

## get
With `undisclosed get KEY` you can retrieve a secret value.

```
$ undisclosed get USER
┌─────────┬────────┬────────┐
│ (index) │  key   │ value  │
├─────────┼────────┼────────┤
│    0    │ 'USER' │ 'root' │
└─────────┴────────┴────────┘
```

## delete
With `undisclosed delete KEY` you can delete a secret.

```
$ undisclosed delete USER

Secret deleted.
```

## dump
With `undisclosed dump` you can dump all the stored secrets decrypted into a `.env` file.

---
_Source: https://npm.io/package/undisclosed · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
