{"_id":"@adewale0o/envlock","_rev":"4-6ccffc8f138cea1f13631ef94f46dd4a","name":"@adewale0o/envlock","dist-tags":{"latest":"1.3.0"},"versions":{"1.0.0":{"name":"@adewale0o/envlock","version":"1.0.0","keywords":["ai-agents","credentials","vault","security","api-keys","env","secrets","cli"],"author":{"name":"John & Neo"},"license":"MIT","_id":"@adewale0o/envlock@1.0.0","maintainers":[{"name":"adewale0o","email":"akmarketing2045@gmail.com"}],"homepage":"https://github.com/Atum246/envlock#readme","bugs":{"url":"https://github.com/Atum246/envlock/issues"},"bin":{"el":"src/index.js","envlock":"src/index.js"},"dist":{"shasum":"0ae8bae43084c90fb3840e92fe1fb16f742033dd","tarball":"https://registry.npmjs.org/@adewale0o/envlock/-/envlock-1.0.0.tgz","fileCount":17,"integrity":"sha512-SdETyPWGzT/3688FvHGJ89zscwBUqlx6cPxTGuJwKUySJ672BFzK1DN6GIig4FHjpewtL+vtoo1UmL/jWCzSxg==","signatures":[{"sig":"MEUCICsZzVTUycdWFBSh4Hupwo15Ub0i8MIHcBjvW2pKfZWUAiEAzTvFU7lwSJyKgpuNBly1R9AVkvXYwVw3w2PmG1xzpWs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":182833},"main":"src/index.js","engines":{"node":">=14.0.0"},"gitHead":"dd171eef6f4d13f042e1d3d1021c00da6b6f7b2f","scripts":{"test":"node tests/test.js","start":"node src/index.js"},"_npmUser":{"name":"adewale0o","email":"akmarketing2045@gmail.com"},"repository":{"url":"git+https://github.com/Atum246/envlock.git","type":"git"},"_npmVersion":"10.9.4","description":"🔐 Envlock — Secure credential vault for AI agents. Store, manage, and inject API keys without exposing them in chat.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ora":"^5.4.1","conf":"^10.2.0","boxen":"^5.1.2","chalk":"^4.1.2","inquirer":"^8.2.6","commander":"^11.0.0","crypto-js":"^4.2.0","cli-table3":"^0.6.3","clipboardy":"^2.3.0","gradient-string":"^2.0.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/envlock_1.0.0_1777668905272_0.5404456510385691","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@adewale0o/envlock","version":"1.1.0","keywords":["ai-agents","credentials","vault","security","api-keys","env","secrets","cli"],"author":{"name":"John & Neo"},"license":"MIT","_id":"@adewale0o/envlock@1.1.0","maintainers":[{"name":"adewale0o","email":"akmarketing2045@gmail.com"}],"homepage":"https://github.com/Atum246/envlock#readme","bugs":{"url":"https://github.com/Atum246/envlock/issues"},"bin":{"el":"src/index.js","envlock":"src/index.js"},"dist":{"shasum":"b91c8e6a1b61204bb23e50ad8fb16035004791f0","tarball":"https://registry.npmjs.org/@adewale0o/envlock/-/envlock-1.1.0.tgz","fileCount":17,"integrity":"sha512-1Q94uuGv+ePSQzZunQ1Jch4fPemMMkFihstEi8x0uJIGASyCZsWC5Itwgoxd4Ic9FLaKjYzDSHmKovq2Ildb7A==","signatures":[{"sig":"MEUCIGhKsqQgZtiNCkuhzAr2ioia0IvhNpX385P6HSV9uaYDAiEArx1C8yXBHaunwVrJypG8+fFsyCpKVIqJKokZFcsLybM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":185507},"main":"src/index.js","engines":{"node":">=14.0.0"},"gitHead":"05a44ade2f4da2ccb7ba27c0c997d95bdfb279d6","scripts":{"test":"node tests/test.js","start":"node src/index.js"},"_npmUser":{"name":"adewale0o","email":"akmarketing2045@gmail.com"},"repository":{"url":"git+https://github.com/Atum246/envlock.git","type":"git"},"_npmVersion":"10.9.4","description":"🔐 Envlock — Secure credential vault for AI agents. Store, manage, and inject API keys without exposing them in chat.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ora":"^5.4.1","conf":"^10.2.0","boxen":"^5.1.2","chalk":"^4.1.2","inquirer":"^8.2.6","commander":"^11.0.0","crypto-js":"^4.2.0","cli-table3":"^0.6.3","clipboardy":"^2.3.0","gradient-string":"^2.0.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/envlock_1.1.0_1777669258392_0.5816898985186403","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@adewale0o/envlock","version":"1.2.0","keywords":["ai-agents","credentials","vault","security","api-keys","env","secrets","cli"],"author":{"name":"John & Neo"},"license":"MIT","_id":"@adewale0o/envlock@1.2.0","maintainers":[{"name":"adewale0o","email":"akmarketing2045@gmail.com"}],"homepage":"https://github.com/Atum246/envlock#readme","bugs":{"url":"https://github.com/Atum246/envlock/issues"},"bin":{"el":"src/index.js","envlock":"src/index.js"},"dist":{"shasum":"b031258cafad70514d7b6c7731119caabce74a9d","tarball":"https://registry.npmjs.org/@adewale0o/envlock/-/envlock-1.2.0.tgz","fileCount":17,"integrity":"sha512-dYNl2PAnSXdwFFLbR0sEV//0PbyEoecszZQr7+d0UCu4Sr0TgtWuiAyw4hUZT5x6hTkVl5vQg9Y2VPhZWDWLZQ==","signatures":[{"sig":"MEUCIHBCaO0NIfXYH56zO5xte8SjRT+QLLCJE7qKix2NeBHHAiEAj+teUhBWLk9JQPRBUrW5h1EPIEEpZ+4V7RVAd5vK5e0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":189797},"main":"src/index.js","engines":{"node":">=14.0.0"},"gitHead":"a07ed56d5d5075047e9028179b7c66150293d988","scripts":{"test":"node tests/test.js","start":"node src/index.js"},"_npmUser":{"name":"adewale0o","email":"akmarketing2045@gmail.com"},"repository":{"url":"git+https://github.com/Atum246/envlock.git","type":"git"},"_npmVersion":"10.9.4","description":"🔐 Envlock — Secure credential vault for AI agents. Store, manage, and inject API keys without exposing them in chat.","directories":{},"_nodeVersion":"22.22.1","dependencies":{"ora":"^5.4.1","conf":"^10.2.0","boxen":"^5.1.2","chalk":"^4.1.2","inquirer":"^8.2.6","commander":"^11.0.0","crypto-js":"^4.2.0","cli-table3":"^0.6.3","clipboardy":"^2.3.0","gradient-string":"^2.0.2"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/envlock_1.2.0_1777669457119_0.3838611486084236","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@adewale0o/envlock","version":"1.3.0","description":"🔐 Envlock — Secure credential vault for AI agents. Store, manage, and inject API keys without exposing them in chat.","main":"src/index.js","bin":{"envlock":"src/index.js","el":"src/index.js"},"scripts":{"test":"node tests/test.js","start":"node src/index.js"},"keywords":["ai-agents","credentials","vault","security","api-keys","env","secrets","cli"],"author":{"name":"John & Neo"},"license":"MIT","dependencies":{"commander":"^11.0.0","chalk":"^4.1.2","inquirer":"^8.2.6","ora":"^5.4.1","crypto-js":"^4.2.0","conf":"^10.2.0","cli-table3":"^0.6.3","gradient-string":"^2.0.2","boxen":"^5.1.2","clipboardy":"^2.3.0"},"engines":{"node":">=14.0.0"},"repository":{"type":"git","url":"git+https://github.com/Atum246/envlock.git"},"homepage":"https://atum246.github.io/envlock/","_id":"@adewale0o/envlock@1.3.0","gitHead":"9554883d59bd07c229577c7fbaaf81e87ca0318e","bugs":{"url":"https://github.com/Atum246/envlock/issues"},"_nodeVersion":"22.22.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-W8SdbkkXnU3NDJ6kVxjm+HcNcRJq8vgiB54cCFhduN9Cxnp7QBvhwqxIijgd4R7LbSQixLt3LeLuVjNMgoNcNw==","shasum":"3feb59b049f500819c3cffd8249173af46ec4a74","tarball":"https://registry.npmjs.org/@adewale0o/envlock/-/envlock-1.3.0.tgz","fileCount":18,"unpackedSize":232763,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIAl/rFqKFuEQerECjHEYjLD5doWjqZU0ZVpakUApr5WEAiBc6jWF/AvpMux0fdKLZq+LUQEGYlymdj3oGPe5NDMMAw=="}]},"_npmUser":{"name":"adewale0o","email":"akmarketing2045@gmail.com"},"directories":{},"maintainers":[{"name":"adewale0o","email":"akmarketing2045@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/envlock_1.3.0_1777669866184_0.32506654584485317"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-01T20:55:05.164Z","modified":"2026-05-01T21:11:06.414Z","1.0.0":"2026-05-01T20:55:05.443Z","1.1.0":"2026-05-01T21:00:58.578Z","1.2.0":"2026-05-01T21:04:17.304Z","1.3.0":"2026-05-01T21:11:06.313Z"},"bugs":{"url":"https://github.com/Atum246/envlock/issues"},"author":{"name":"John & Neo"},"license":"MIT","homepage":"https://atum246.github.io/envlock/","keywords":["ai-agents","credentials","vault","security","api-keys","env","secrets","cli"],"repository":{"type":"git","url":"git+https://github.com/Atum246/envlock.git"},"description":"🔐 Envlock — Secure credential vault for AI agents. Store, manage, and inject API keys without exposing them in chat.","maintainers":[{"name":"adewale0o","email":"akmarketing2045@gmail.com"}],"readme":"<p align=\"center\">\n  <pre align=\"center\">\n  ███████╗███╗   ██╗██╗   ██╗██╗      ██████╗  ██████╗██╗  ██╗\n  ██╔════╝████╗  ██║██║   ██║██║     ██╔═══██╗██╔════╝██║ ██╔╝\n  █████╗  ██╔██╗ ██║██║   ██║██║     ██║   ██║██║     █████╔╝\n  ██╔══╝  ██║╚██╗██║██║   ██║██║     ██║   ██║██║     ██╔═██╗\n  ███████╗██║ ╚████║╚██████╔╝███████╗╚██████╔╝╚██████╗██║  ██╗\n  ╚══════╝╚═╝  ╚═══╝ ╚═════╝ ╚══════╝ ╚═════╝  ╚═════╝╚═╝  ╚═╝\n  </pre>\n</p>\n\n<p align=\"center\">\n  <strong>🔐 Secure Credential Vault for AI Agents</strong>\n</p>\n\n<p align=\"center\">\n  <code>npm install -g envlock</code>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://atum246.github.io/envlock/\">Website</a> •\n  <a href=\"#-quick-start\">Quick Start</a> •\n  <a href=\"#-for-ai-agents\">For AI Agents</a> •\n  <a href=\"#-web-ui\">Web UI</a> •\n  <a href=\"#-46-service-templates\">Templates</a> •\n  <a href=\"#-commands\">Commands</a> •\n  <a href=\"#-security\">Security</a> •\n  <a href=\"#-contributing\">Contributing</a>\n</p>\n\n---\n\n<p align=\"center\">\n  <pre align=\"center\">\n       .-\"\"\"-.\n      /        \\\n     |  .--.  |\n     | |    | |\n     | | 🔒 | |\n     | |    | |\n     |  '--'  |\n      \\      /\n       '-..-'\n  </pre>\n</p>\n\n> **Stop pasting API keys into chat. Store them securely. Let your AI agent access them safely.**\n\n---\n\n## 🤔 The Problem\n\nEvery day, millions of users paste API keys, tokens, passwords, and credentials directly into AI chat interfaces. This is **dangerous**:\n\n| Risk | What Happens |\n|------|-------------|\n| 📝 **Conversation History** | Keys get stored on AI provider servers — forever |\n| 🔓 **Data Breaches** | If the provider gets hacked, your keys are exposed |\n| 🎣 **Prompt Injection** | Malicious prompts can trick the AI into leaking your keys |\n| 🤖 **Training Data** | Keys might end up in model training data |\n| 👀 **Screen Sharing** | Anyone who sees the chat sees your secrets |\n| 💀 **No Revocation** | You can't \"un-paste\" a key from chat history |\n\n## 💡 The Solution: Envlock\n\nEnvlock is a **secure local vault** that sits between users and AI agents. Instead of pasting keys into chat, users input them through a **secure web form**, and AI agents read them through a **safe API**.\n\n```\n❌ OLD WAY:\nUser → [pastes key in chat] → AI Agent → External API\n         ↑\n    Key exposed in chat history, logs, training data\n\n✅ ENVLOCK WAY:\nUser → [pastes key in web form] → Encrypted Vault → AI Agent → External API\n              ↑                         ↑\n    Never enters chat            Encrypted at rest\n    Localhost only               Agent reads via API\n```\n\n---\n\n## ⚡ Quick Start\n\n### Step 1: Install (AI Agent does this)\n\n```bash\nnpm install -g @adewale0o/envlock\n```\n\n### Step 2: Initialize (AI Agent does this)\n\n```bash\nenvlock init\n# You'll set a master password. This encrypts everything.\n```\n\n### Step 3: Start Web UI (AI Agent does this)\n\n**If agent and user are on the same computer:**\n```bash\nenvlock serve\n# → http://127.0.0.1:3847/?token=abc123...\n```\n\n**If agent is on a server and user is on a different device:**\n```bash\nenvlock serve --expose\n# → http://192.168.1.100:3847/?token=abc123...\n```\n\n### Step 4: User Opens Link (User does this)\n\nThe agent tells the user: *\"Open this link to add your API keys\"*\n\nThe user:\n1. Opens the URL in their browser\n2. Sees a clean form with service templates (OpenAI, Stripe, Discord, etc.)\n3. Picks the service they want\n4. Pastes their API key into the form\n5. Clicks \"Save Securely\"\n6. Done! Key is encrypted in the vault. Never touched chat.\n\n### Step 5: Agent Reads Keys (AI Agent does this)\n\n```bash\nenvlock get OPENAI_API_KEY\n# → sk-1234567890...\n```\n\n### The Complete Flow\n\n```\n┌─────────────┐         ┌──────────────┐         ┌─────────────┐\n│   User      │         │   Envlock    │         │  AI Agent   │\n│             │         │   (Vault)    │         │             │\n│ Opens link  │────────▶│ Web form     │         │             │\n│ Picks svc   │         │ AES-256      │         │             │\n│ Pastes key  │────────▶│ Encrypts     │         │             │\n│             │         │ Stores       │         │             │\n│             │         │              │◀────────│ Reads key   │\n│             │         │              │         │ Calls API   │\n│             │         │              │         │ Done ✅     │\n└─────────────┘         └──────────────┘         └─────────────┘\n\nKey NEVER enters chat. Key NEVER leaves localhost. Key is ALWAYS encrypted.\n```\n\n---\n\n## 🤖 For AI Agents\n\nEnvlock is designed **specifically for AI agents** to install and manage. Here's how different agents use it:\n\n### OpenClaw\n\n```bash\n# OpenClaw agent runs:\nnpm install -g envlock && envlock init\n\n# Agent starts web UI, gets URL\nenvlock serve\n# → \"Open http://127.0.0.1:3847/?token=xxx to add your keys\"\n\n# Agent tells user the URL\n# User opens link, adds keys\n# Agent reads keys via:\nenvlock get OPENAI_API_KEY --raw\n```\n\n### Claude Code\n\n```bash\n# Claude Code can install and use Envlock:\nnpm install -g envlock\n\n# Initialize vault\nenvlock init\n\n# Create slots for needed keys\nenvlock create ANTHROPIC_API_KEY -d \"Anthropic API key\" -t api_key\n\n# Start web UI for user input\nenvlock serve\n\n# Later, read keys programmatically\nenvlock api get ANTHROPIC_API_KEY --json\n```\n\n### Cursor / Windsurf / Any AI Agent\n\n```bash\n# Any AI agent can use the JSON API\nenvlock api list --json\nenvlock api get KEY_NAME --json\nenvlock api create NEW_KEY --json\nenvlock api set NEW_KEY --json\nenvlock api export --json\n```\n\n### Agent API Reference\n\nAll agent API calls return JSON and support `--json` flag:\n\n```bash\n# List all secrets\nenvlock api list --json\n# → {\"success\": true, \"slots\": [{\"name\": \"OPENAI_API_KEY\", \"type\": \"api_key\", ...}]}\n\n# Get a specific secret\nenvlock api get OPENAI_API_KEY --json\n# → {\"success\": true, \"slot\": \"OPENAI_API_KEY\", \"value\": \"sk-...\"}\n\n# Create a new slot\nenvlock api create NEW_KEY --json\n# → {\"success\": true, \"slot\": \"NEW_KEY\"}\n\n# Set a value\nenvlock api set NEW_KEY --json\n# → {\"success\": true, \"slot\": \"NEW_KEY\"}\n\n# Export all secrets as env vars\nenvlock api export --json\n# → {\"success\": true, \"secrets\": {\"KEY1\": \"val1\", \"KEY2\": \"val2\"}}\n\n# Check vault status\nenvlock api status --json\n# → {\"success\": true, \"initialized\": true, \"locked\": false, \"slots\": 5}\n```\n\n### Agent Permissions\n\nWhen registering agents, you can set granular permissions:\n\n```bash\n# Register with specific permissions\nenvlock api register --json\n# Permissions: read, list, write, create, delete, execute\n\n# Scoped access — agent only sees specific slots\nenvlock api register --json\n# allowedSlots: [\"OPENAI_API_KEY\", \"STRIPE_KEY\"]\n```\n\n---\n\n## 🌐 Web UI — The Core Feature\n\nThe web UI is **why Envlock exists** — instead of pasting API keys into chat (where they get logged, stored, and potentially leaked), users paste them into a **clean web form** that goes straight into an encrypted vault.\n\n```\n❌ DON'T DO THIS:\nUser: \"here's my API key: sk-1234567890...\"\n→ Key is now in chat history, logs, training data\n\n✅ DO THIS INSTEAD:\nAgent: \"Open http://127.0.0.1:3847/?token=xxx to add your keys\"\nUser: *opens link, picks OpenAI, pastes key in form*\n→ Key goes directly into encrypted vault. Never in chat.\n```\n\n---\n\n### Two Modes — Which One Do I Use?\n\n#### Mode 1: Localhost (Default)\n\n```bash\nenvlock serve\n```\n\n```\nYour Computer\n┌──────────────────────────────┐\n│  AI Agent (OpenClaw, etc.)   │\n│         ↓                    │\n│  Envlock Vault (encrypted)   │\n│         ↓                    │\n│  Web UI at 127.0.0.1:3847   │◄── Only accessible from THIS machine\n└──────────────────────────────┘\n```\n\n**When to use:**\n- ✅ AI agent runs on YOUR computer (Cursor, Claude Code desktop, OpenClaw local)\n- ✅ You open the browser on the SAME machine\n- ✅ Most secure — nothing leaves your computer\n\n**How it works:**\n1. Agent runs `envlock serve`\n2. Agent gives you the URL: `http://127.0.0.1:3847/?token=abc123`\n3. You open that URL in your browser ON THE SAME COMPUTER\n4. You see the form, pick a service, paste your key\n5. Key is encrypted and stored locally\n6. Agent reads it when needed\n\n**Who can access:** Only you, from the same machine. Nobody else can reach `127.0.0.1`.\n\n---\n\n#### Mode 2: Network Exposed (`--expose`)\n\n```bash\nenvlock serve --expose\n```\n\n```\nYour VPS/Server                    Your Laptop/Phone\n┌──────────────────────┐          ┌──────────────┐\n│  AI Agent            │          │  Browser     │\n│         ↓            │          │              │\n│  Envlock Vault       │◄─────────│  You open    │\n│         ↓            │ network  │  the URL     │\n│  Web UI at           │          │              │\n│  0.0.0.0:3847        │          └──────────────┘\n└──────────────────────┘\n```\n\n**When to use:**\n- ✅ AI agent runs on a VPS/cloud server (DigitalOcean, AWS, etc.)\n- ✅ You want to add keys from your laptop or phone\n- ✅ You're on the same WiFi/LAN network as the server\n\n**How it works:**\n1. Agent runs `envlock serve --expose` on the server\n2. Agent gives you the URL: `http://192.168.1.100:3847/?token=abc123`\n3. You open that URL from ANY device on the same network\n4. You see the form, pick a service, paste your key\n5. Key is encrypted and stored on the server\n6. Agent reads it when needed\n\n**Who can access:** Anyone on the same network who has the token URL. The token is required — without it, you just see a \"enter token\" page.\n\n---\n\n### Quick Decision Guide\n\n| Your Setup | Command | Why |\n|------------|---------|-----|\n| Agent on my laptop, I use my laptop | `envlock serve` | Same machine = localhost is enough |\n| Agent on a VPS, I use my laptop | `envlock serve --expose` | Different machines = need network access |\n| Agent on a VPS, I'm on the internet | `envlock serve --expose` + firewall/port forward | Need to open port on your VPS |\n| Just me, just testing | `envlock serve` | Simplest option |\n\n---\n\n### Security — Is This Safe?\n\n**Yes.** Here's why:\n\n| Layer | Protection |\n|-------|-----------|\n| 🔑 **Token auth** | URL contains a random 32-char token. No token = no access |\n| 🏠 **Localhost default** | Only exposed to the internet if YOU choose `--expose` |\n| 🔐 **Encrypted** | All secrets are AES-256 encrypted on disk |\n| 🚫 **No chat** | Keys never enter conversation history |\n| 📋 **Audit log** | Every access is logged with timestamp |\n| ⏰ **One-time token** | Token changes each time you restart `envlock serve` |\n\n**Even with `--expose`:**\n- The server only listens on your local network (LAN), not the internet\n- A random token is required for every request\n- Without the token, you see nothing useful\n- The token changes every restart\n\n---\n\n### Web UI Features\n\n| Feature | Description |\n|---------|-------------|\n| 🎨 **Clean Dark UI** | Purple-themed, minimal, not generic AI slop |\n| 📋 **46 Templates** | Pick OpenAI, Stripe, Discord, AWS, etc. |\n| 📝 **Bulk Add** | Paste multiple `NAME=value` pairs at once |\n| 📥 **Import .env** | Paste your existing `.env` file |\n| 🔐 **Encrypted** | All data encrypted immediately |\n| 🔑 **Token Protected** | URL contains one-time access token |\n\n### What Users See\n\n**Dashboard:**\n```\n┌──────────────────────────────────────────────┐\n│  🔐 Envlock          5 secrets    [+ Add]    │\n├──────────────────────────────────────────────┤\n│  Your Secrets                                │\n│  ┌─────────┐ ┌─────────┐ ┌─────────┐        │\n│  │ 🔑      │ │ 🎫      │ │ 🔒      │        │\n│  │ OPENAI  │ │ STRIPE  │ │ DB_URL  │        │\n│  │ ✅ Set  │ │ ✅ Set  │ │ ✅ Set  │        │\n│  └─────────┘ └─────────┘ └─────────┘        │\n│                                              │\n│  Add by Service                              │\n│  🤖 AI & Machine Learning                    │\n│  ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐           │\n│  │OpenAI│ │Anthro│ │Gemini│ │ HF  │           │\n│  └─────┘ └─────┘ └─────┘ └─────┘           │\n│  📱 Social Media                             │\n│  ┌─────┐ ┌─────┐ ┌─────┐ ┌─────┐           │\n│  │Twittr│ │Discrd│ │Telegr│ │Slack│           │\n│  └─────┘ └─────┘ └─────┘ └─────┘           │\n└──────────────────────────────────────────────┘\n```\n\n**Add Secret Form (e.g., OpenAI):**\n```\n┌──────────────────────────────────────────────┐\n│  ← Back        🤖 OpenAI                     │\n├──────────────────────────────────────────────┤\n│                                              │\n│  API Key *                                   │\n│  ┌──────────────────────────────────────┐    │\n│  │ sk-...                          👁️  │    │\n│  └──────────────────────────────────────┘    │\n│                                              │\n│  Organization ID                             │\n│  ┌──────────────────────────────────────┐    │\n│  │ org-...                             │    │\n│  └──────────────────────────────────────┘    │\n│                                              │\n│  ┌──────────────────────────────────────┐    │\n│  │        🔐 Save Securely              │    │\n│  └──────────────────────────────────────┘    │\n└──────────────────────────────────────────────┘\n```\n\n---\n\n## 📦 46 Service Templates\n\nPre-built forms so users don't have to figure out field names. Agents can use templates programmatically:\n\n```bash\n# List all templates\nenvlock templates\n\n# List by category\nenvlock templates -c social\n\n# Use a template interactively\nenvlock from-template openai\n\n# Use via web UI\n# → http://127.0.0.1:PORT/add?template=openai&token=xxx\n```\n\n### 🤖 AI & Machine Learning (5)\n| ID | Service | Fields |\n|----|---------|--------|\n| `openai` | OpenAI | API Key, Org ID |\n| `anthropic` | Anthropic (Claude) | API Key |\n| `google-ai` | Google AI (Gemini) | API Key |\n| `huggingface` | Hugging Face | Access Token |\n| `replicate` | Replicate | API Token |\n\n### 📱 Social Media (11)\n| ID | Service | Fields |\n|----|---------|--------|\n| `twitter` | Twitter / X | API Key, API Secret, Access Token, Access Secret, Bearer Token |\n| `discord` | Discord | Bot Token, Client ID, Client Secret |\n| `telegram` | Telegram | Bot Token, Chat ID |\n| `slack` | Slack | Bot Token, App Token, Webhook URL |\n| `instagram` | Instagram | Username, Password, Access Token |\n| `facebook` | Facebook / Meta | Access Token, App ID, App Secret |\n| `linkedin` | LinkedIn | Access Token, Client ID, Client Secret |\n| `youtube` | YouTube / Google | API Key, Client ID, Client Secret, Refresh Token |\n| `tiktok` | TikTok | Access Token, Client Key, Client Secret |\n| `reddit` | Reddit | Client ID, Client Secret, Username, Password |\n| `pinterest` | Pinterest | Access Token, App ID |\n\n### 🛠️ Developer Tools (1)\n| ID | Service | Fields |\n|----|---------|--------|\n| `github` | GitHub | Personal Access Token, Username |\n\n### ☁️ Cloud & Infrastructure (7)\n| ID | Service | Fields |\n|----|---------|--------|\n| `aws` | AWS | Access Key ID, Secret Access Key, Region, Session Token |\n| `gcp` | Google Cloud | Project ID, Service Account JSON |\n| `azure` | Azure | Client ID, Client Secret, Tenant ID, Subscription ID |\n| `vercel` | Vercel | API Token |\n| `netlify` | Netlify | Auth Token |\n| `digitalocean` | DigitalOcean | API Token |\n| `flyio` | Fly.io | API Token |\n\n### 🗄️ Databases (6)\n| ID | Service | Fields |\n|----|---------|--------|\n| `postgres` | PostgreSQL | Connection URL, Host, Port, User, Password, Database |\n| `mysql` | MySQL | Connection URL, Host, User, Password, Database |\n| `mongodb` | MongoDB | Connection URI |\n| `redis` | Redis | Connection URL |\n| `firebase` | Firebase | API Key, Auth Domain, Project ID, Service Account |\n| `supabase` | Supabase | Project URL, Anon Key, Service Role Key |\n\n### 💳 Payments (2)\n| ID | Service | Fields |\n|----|---------|--------|\n| `stripe` | Stripe | Secret Key, Publishable Key, Webhook Secret |\n| `paypal` | PayPal | Client ID, Client Secret, Mode |\n\n### 📧 Email & Communication (3)\n| ID | Service | Fields |\n|----|---------|--------|\n| `sendgrid` | SendGrid | API Key |\n| `mailgun` | Mailgun | API Key, Domain |\n| `twilio` | Twilio | Account SID, Auth Token, Phone Number |\n\n### 📊 Analytics & Monitoring (3)\n| ID | Service | Fields |\n|----|---------|--------|\n| `datadog` | Datadog | API Key, Application Key |\n| `sentry` | Sentry | DSN, Auth Token |\n| `newrelic` | New Relic | License Key, App Name |\n\n### 🚀 DevOps & CI/CD (2)\n| ID | Service | Fields |\n|----|---------|--------|\n| `docker` | Docker Hub | Username, Password |\n| `npm` | npm | Access Token |\n\n### 🛡️ VPN & Network (2)\n| ID | Service | Fields |\n|----|---------|--------|\n| `vpn` | VPN Credentials | Server, Username, Password, Config |\n| `ssh` | SSH Key | Host, Username, Private Key, Passphrase |\n\n### 🔧 Custom / Generic (4)\n| ID | Service | Fields |\n|----|---------|--------|\n| `api-key` | Generic API Key | API Key, API Secret, Base URL |\n| `oauth` | OAuth Credentials | Client ID, Client Secret, Redirect URI, Access Token, Refresh Token |\n| `basic-auth` | Username & Password | Username, Password |\n| `bearer-token` | Bearer Token | Token, Base URL |\n\n---\n\n## 📋 Commands\n\n### Core Vault\n\n| Command | Description |\n|---------|-------------|\n| `envlock init` | Initialize vault with master password |\n| `envlock create <name>` | Create a new secret slot |\n| `envlock set <name>` | Set value for a secret |\n| `envlock get <name>` | Retrieve a secret |\n| `envlock delete <name>` | Delete a secret |\n| `envlock list` | List all secret slots |\n| `envlock status` | Show vault status |\n\n### Web UI & Templates\n\n| Command | Description |\n|---------|-------------|\n| `envlock serve` | 🌐 Start web UI for users to input secrets |\n| `envlock templates` | 📋 List 46 service templates |\n| `envlock from-template <id>` | ➕ Add credentials from a template |\n| `envlock import-env <file>` | 📥 Import secrets from a .env file |\n\n### Generation & Analysis\n\n| Command | Description |\n|---------|-------------|\n| `envlock generate` | 🔐 Generate passwords, API keys, tokens, UUIDs |\n| `envlock strength [pwd]` | 💪 Analyze password strength |\n| `envlock health [name]` | 🏥 Check credential format validity |\n\n### Organization\n\n| Command | Description |\n|---------|-------------|\n| `envlock search <query>` | 🔍 Search secrets by name, description, or tags |\n| `envlock tag <name> <tags>` | 🏷️ Add tags to a secret |\n| `envlock fav <name>` | ⭐ Toggle favorite status |\n| `envlock history [name]` | 📜 View change history |\n| `envlock profiles` | 📁 Manage environment profiles (dev/staging/prod) |\n\n### Security & Sharing\n\n| Command | Description |\n|---------|-------------|\n| `envlock lock` | 🔒 Lock the vault |\n| `envlock unlock` | 🔓 Unlock the vault |\n| `envlock rotate` | 🔄 Change master password |\n| `envlock backup` | 💾 Create encrypted backup |\n| `envlock restore <id>` | ♻️ Restore from backup |\n| `envlock backups` | 📋 List backups |\n| `envlock share <name>` | 🔗 Create shareable encrypted bundle |\n| `envlock import <bundle>` | 📥 Import encrypted bundle |\n\n### Export & Injection\n\n| Command | Description |\n|---------|-------------|\n| `envlock export` | Export secrets as env vars (shell/dotenv/docker/json) |\n| `envlock inject <cmd>` | Run a command with secrets injected |\n| `envlock api <method>` | 🤖 Agent API (JSON in/out) |\n\n### System\n\n| Command | Description |\n|---------|-------------|\n| `envlock audit` | 📋 View audit log |\n| `envlock config` | ⚙️ View/set configuration |\n\n---\n\n## 🔒 Security\n\n### Encryption\n\n| Layer | Algorithm | Details |\n|-------|-----------|---------|\n| **Vault** | AES-256-CBC | All secrets encrypted at rest |\n| **Key Derivation** | PBKDF2 | 100,000 iterations, SHA-256 |\n| **File Permissions** | `0600` | Owner-only read/write |\n| **Web UI** | Token-protected | One-time access token in URL |\n| **Network** | Localhost only | Never exposed to internet |\n\n### What Gets Stored\n\n```\n~/.envlock/\n├── vault.enc           # 🔐 Your encrypted secrets\n├── slots.enc           # 🔐 Slot metadata (names, types, tags)\n├── meta.json           # 📋 Vault metadata\n├── config.json         # ⚙️ Configuration\n├── audit.json          # 📋 Audit log\n├── agents.json         # 🤖 Registered agents\n├── agent-requests.json # 📝 Pending access requests\n├── profiles/           # 📁 Environment profiles\n├── history/            # 📜 Change history\n└── backups/            # 💾 Encrypted backups\n```\n\n### Audit Log\n\nEvery action is logged with timestamp and details:\n\n```bash\nenvlock audit\n```\n\n```\n📋 Envlock Audit Log:\n\n┌─────────────────────────────┬─────────────────┬───────────────────┐\n│ Time                        │ Event           │ Details           │\n├─────────────────────────────┼─────────────────┼───────────────────┤\n│ 5/2/2026, 4:30:00 AM       │ vault_init      │ -                 │\n│ 5/2/2026, 4:30:05 AM       │ slot_created    │ {\"name\":\"OPENAI\"} │\n│ 5/2/2026, 4:30:10 AM       │ secret_set      │ {\"name\":\"OPENAI\"} │\n│ 5/2/2026, 4:31:00 AM       │ secret_accessed │ {\"name\":\"OPENAI\"} │\n│ 5/2/2026, 4:32:00 AM       │ webui_started   │ {\"port\":3847}     │\n└─────────────────────────────┴─────────────────┴───────────────────┘\n```\n\n---\n\n## 🎯 Export Formats\n\n```bash\n# Shell\nenvlock export --format shell\nexport OPENAI_API_KEY=\"sk-...\"\nexport STRIPE_SECRET_KEY=\"sk_live_...\"\n\n# dotenv\nenvlock export --format dotenv\nOPENAI_API_KEY=\"sk-...\"\nSTRIPE_SECRET_KEY=\"sk_live_...\"\n\n# Docker\nenvlock export --format docker\n-e OPENAI_API_KEY=\"sk-...\" -e STRIPE_SECRET_KEY=\"sk_live_...\"\n\n# JSON\nenvlock export --format json\n{\"OPENAI_API_KEY\": \"sk-...\", \"STRIPE_SECRET_KEY\": \"sk_live_...\"}\n```\n\n### Inject into Commands\n\n```bash\n# Run any command with secrets as env vars\nenvlock inject node app.js\nenvlock inject python main.py\nenvlock inject docker compose up\n```\n\n---\n\n## 🔐 Password Generator\n\nGenerate secure passwords, API keys, tokens, and UUIDs:\n\n```bash\n# Generate a password\nenvlock generate --type password --length 32\n\n# Generate an API key with prefix\nenvlock generate --type apikey --prefix sk\n\n# Generate a token\nenvlock generate --type token --length 64\n\n# Generate a UUID\nenvlock generate --type uuid\n\n# Generate and save directly\nenvlock generate --type password --length 24 --save MY_PASSWORD\n\n# Analyze password strength\nenvlock strength \"MyP@ssw0rd!\"\n# → Score: 🔐 Excellent\n# → Entropy: ~72 bits\n# → Length: 12 chars\n```\n\n---\n\n## 📁 Environment Profiles\n\nManage separate secrets for different environments:\n\n```bash\n# Create profiles\nenvlock profiles --create dev\nenvlock profiles --create staging\nenvlock profiles --create prod\n\n# List profiles\nenvlock profiles\n\n# Compare profiles\nenvlock profiles --diff dev,prod\n```\n\n---\n\n## 🏥 Health Checks\n\nValidate that your credentials are correctly formatted:\n\n```bash\n# Check all secrets\nenvlock health\n\n# Check a specific secret\nenvlock health OPENAI_API_KEY\n```\n\n```\n🏥 Credential Health Check:\n\n┌────────────────────┬──────────┬──────────┐\n│ Secret             │ Format   │ Details  │\n├────────────────────┼──────────┼──────────┤\n│ OPENAI_API_KEY     │ ✅ Valid │ OpenAI   │\n│ GITHUB_TOKEN       │ ✅ Valid │ GitHub   │\n│ SHORT_KEY          │ ⚠️ Check │ Too short│\n└────────────────────┴──────────┴──────────┘\n```\n\n---\n\n## 🔧 Technical Deep Dive — What's Happening in the Background\n\n### The Full Flow (Step by Step)\n\nWhen an AI agent uses Envlock, here's exactly what happens at each layer:\n\n#### 1. Installation\n\n```bash\nnpm install -g @adewale0o/envlock\n```\n\n- npm downloads the package to your global `node_modules`\n- The `envlock` and `el` commands become available globally\n- No background services, no daemons, no system modifications\n- Everything runs on-demand when you invoke a command\n\n#### 2. Initialization (`envlock init`)\n\n```\nUser enters master password\n         ↓\nPBKDF2 derives encryption key (100,000 iterations, SHA-256)\n         ↓\nCreates ~/.envlock/ directory (permissions: 0700)\n         ↓\nCreates vault.enc (AES-256 encrypted, permissions: 0600)\n         ↓\nCreates slots.enc (encrypted metadata, permissions: 0600)\n         ↓\nCreates meta.json, config.json, audit.json\n```\n\n**What's stored on disk:**\n- `~/.envlock/vault.enc` — Your secrets, encrypted with AES-256-CBC\n- `~/.envlock/slots.enc` — Slot metadata (names, types, tags), also encrypted\n- `~/.envlock/meta.json` — Vault creation date, version (not encrypted, no secrets)\n- `~/.envlock/config.json` — Your preferences (not encrypted, no secrets)\n- `~/.envlock/audit.json` — Access log (not encrypted, no secrets)\n\n#### 3. Web UI (`envlock serve`)\n\n```\nenvlock serve\n      ↓\nGenerates random 32-char access token\n      ↓\nStarts HTTP server on 127.0.0.1:RANDOM_PORT (or 0.0.0.0 with --expose)\n      ↓\nServes HTML/CSS/JS directly from memory (no external dependencies)\n      ↓\nUser opens URL with token in browser\n      ↓\nToken is validated on every request (query param or header)\n      ↓\nUser fills form → POST /api/secret → encrypted immediately → saved to vault.enc\n      ↓\nServer runs until Ctrl+C\n```\n\n**The web server:**\n- Pure Node.js `http.createServer` — no Express, no frameworks\n- All HTML/CSS/JS is embedded in the source code (no external assets)\n- Token is required for every API request\n- Without token, user sees a \"enter token\" page\n- Server binds to localhost by default (127.0.0.1)\n- With `--expose`, binds to 0.0.0.0 (all network interfaces)\n- CORS headers set for local development\n- No WebSocket, no long-polling — simple HTTP request/response\n\n#### 4. Agent API (`envlock api`)\n\n```bash\nenvlock api get OPENAI_API_KEY --json\n```\n\n```\nAgent calls: envlock api get OPENAI_API_KEY --json\n      ↓\nCLI loads vault.enc, decrypts with master key\n      ↓\nFinds slot OPENAI_API_KEY in slots\n      ↓\nDecrypts value from vault\n      ↓\nOutputs JSON: {\"success\": true, \"slot\": \"OPENAI_API_KEY\", \"value\": \"sk-...\"}\n      ↓\nAgent uses the value to call OpenAI API\n```\n\n**Agent permissions:**\n- Agents register with `envlock api register`\n- Each agent has: `permissions` (read/list/write/create/delete/execute)\n- Each agent has: `allowedSlots` (which secrets they can access, or `*` for all)\n- Rate limiting: max 1000 requests/hour per agent (configurable)\n- All access logged in audit.json\n\n#### 5. Encryption Details\n\n| Layer | Algorithm | Key Size | Details |\n|-------|-----------|----------|---------|\n| Key Derivation | PBKDF2 | 256-bit | 100,000 iterations, SHA-256 |\n| Vault Encryption | AES-256-CBC | 256-bit | Each value encrypted separately |\n| Backup Encryption | AES-256-CBC | 256-bit | Entire vault bundled and encrypted |\n| Share Bundles | AES-256-CBC | 256-bit | Single secret encrypted with bundle password |\n| Profile Export | AES-256-CBC | 256-bit | Profile data encrypted with password |\n\n**How encryption works:**\n1. You set a master password\n2. PBKDF2 turns that password into a 256-bit key (100,000 iterations)\n3. Every secret is individually encrypted with AES-256-CBC using that key\n4. The encrypted data is written to `vault.enc`\n5. Without the master password, the data is unreadable\n6. Even if someone steals `vault.enc`, they can't decrypt it without your password\n\n#### 6. Network Modes Explained\n\n**Localhost Mode (`envlock serve`):**\n```\n┌─────────────────────────────────┐\n│         Your Computer           │\n│                                 │\n│  ┌───────────┐  ┌───────────┐  │\n│  │ AI Agent  │  │ Browser   │  │\n│  │ (Node.js) │  │ (Chrome)  │  │\n│  └─────┬─────┘  └─────┬─────┘  │\n│        │              │         │\n│        └──────┬───────┘         │\n│               │                 │\n│        ┌──────▼──────┐         │\n│        │ Envlock     │         │\n│        │ 127.0.0.1   │         │\n│        └─────────────┘         │\n└─────────────────────────────────┘\n```\n- Server binds to `127.0.0.1` (loopback address)\n- Only processes on THIS machine can connect\n- Your phone, another computer, or the internet CANNOT reach it\n- This is the safest option\n\n**Network Mode (`envlock serve --expose`):**\n```\n┌──────────────────────┐         ┌──────────────────┐\n│    Your VPS/Server   │         │  Your Laptop     │\n│                      │         │                  │\n│  ┌──────────┐        │   LAN   │  ┌──────────┐   │\n│  │AI Agent  │        │  ◄───── │  │ Browser  │   │\n│  └────┬─────┘        │         │  └──────────┘   │\n│       │              │         │                  │\n│  ┌────▼──────┐       │         └──────────────────┘\n│  │Envlock   │       │\n│  │0.0.0.0   │       │\n│  └──────────┘       │\n└──────────────────────┘\n```\n- Server binds to `0.0.0.0` (all network interfaces)\n- Accessible from any device on the same network\n- \"Same network\" means: same WiFi, same LAN, same VPN, or same private cloud network\n- NOT accessible from the internet (unless you open ports on your firewall)\n- Token authentication still required\n\n**What \"same network\" actually means:**\n\n| Scenario | Same Network? | Works? |\n|----------|--------------|--------|\n| Laptop + phone on home WiFi | ✅ Yes | `--expose` works |\n| Two computers in same office | ✅ Yes | `--expose` works |\n| VPS + your laptop via VPN | ✅ Yes | `--expose` works |\n| Your laptop + friend's laptop (different houses) | ❌ No | Need tunnel or port forward |\n| Your laptop + random VPS on internet | ❌ No | Need firewall rule + port forward |\n\n**If you need internet access (advanced):**\n1. Open the port on your VPS firewall (e.g., `ufw allow 3847`)\n2. Use the VPS's public IP: `http://YOUR_VPS_IP:3847/?token=xxx`\n3. Or use a tunnel: `ngrok http 3847` (creates a temporary public URL)\n4. ⚠️ Only do this if you understand the security implications\n\n---\n\n## 🏗️ Architecture\n\n```\nenvlock/\n├── src/\n│   ├── index.js              # Main CLI (33 commands)\n│   └── lib/\n│       ├── vault.js          # 🔐 Core encrypted vault\n│       ├── agent-bridge.js   # 🤖 Agent API system\n│       ├── web-ui.js         # 🌐 Web server + UI\n│       ├── templates.js      # 📦 46 service templates\n│       ├── password-gen.js   # 🔐 Password generator\n│       ├── profiles.js       # 📁 Environment profiles\n│       ├── history.js        # 📜 Change history\n│       ├── health-check.js   # 🏥 Credential validation\n│       ├── backup.js         # 💾 Backup/restore\n│       ├── audit.js          # 📋 Audit logging\n│       ├── config.js         # ⚙️ Configuration\n│       └── logo.js           # 🎨 ASCII art\n├── tests/\n│   └── test.js               # ✅ 42 tests\n├── README.md\n├── LICENSE                   # MIT\n└── package.json\n```\n\n---\n\n## 🤝 Contributing\n\n1. Fork it\n2. Create your branch (`git checkout -b feature/awesome`)\n3. Commit (`git commit -m 'Add awesome feature'`)\n4. Push (`git push origin feature/awesome`)\n5. Open a PR\n\n---\n\n## 📄 License\n\nMIT © [Envlock Contributors](https://github.com/envlock/envlock)\n\n---\n\n<p align=\"center\">\n  <strong>Built with 💜 by John & Neo</strong>\n</p>\n\n<p align=\"center\">\n  <a href=\"https://github.com/envlock/envlock\">GitHub</a> •\n  <a href=\"https://www.npmjs.com/package/envlock\">npm</a> •\n  <a href=\"#-quick-start\">Quick Start</a>\n</p>\n","readmeFilename":"README.md"}