{"_id":"@akalsey/gatepass","_rev":"3-43f8dd0afc6709e03870ea5031db2015","name":"@akalsey/gatepass","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@akalsey/gatepass","version":"0.1.0","keywords":["secrets","credentials","openclaw","agent","pass","gpg"],"author":{"name":"Adam Kalsey"},"license":"MIT","_id":"@akalsey/gatepass@0.1.0","maintainers":[{"name":"akalsey","email":"adam@kalsey.com"}],"homepage":"https://github.com/akalsey/gatepass#readme","bugs":{"url":"https://github.com/akalsey/gatepass/issues"},"bin":{"gatepass":"bin/gatepass.js"},"dist":{"shasum":"7d1dc5e3f537be4d1788a7ae1b5cd5d4932149a3","tarball":"https://registry.npmjs.org/@akalsey/gatepass/-/gatepass-0.1.0.tgz","fileCount":24,"integrity":"sha512-EgyZF4JCb8RDhsAqD2vfU3pcfTs4u4zl9Enl2aBhmsHXIj4CaJb91VWY4diEBBkSy/2rifaotF9Q9EewyU4WqQ==","signatures":[{"sig":"MEYCIQCKqV6ckU4wc6qfitBnmLjN6hQFni3x2imEiVshmx+1vgIhALAeUtuJB1K4Du0mG4zH2XuAsGzLOXexVR+0nrmp4hwB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89060},"main":"src/cli.js","engines":{"node":">=18"},"gitHead":"cc85dba374d5f38c844794d8e212049755655410","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/gatepass.js"},"_npmUser":{"name":"akalsey","email":"adam@kalsey.com"},"repository":{"url":"git+https://github.com/akalsey/gatepass.git","type":"git"},"_npmVersion":"11.13.0","description":"Conversational secrets management for OpenClaw agents","directories":{},"_nodeVersion":"26.0.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/gatepass_0.1.0_1779210535801_0.14986830157512943","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@akalsey/gatepass","version":"0.1.1","keywords":["secrets","credentials","openclaw","agent","pass","gpg"],"author":{"name":"Adam Kalsey"},"license":"MIT","_id":"@akalsey/gatepass@0.1.1","maintainers":[{"name":"akalsey","email":"adam@kalsey.com"}],"homepage":"https://github.com/akalsey/gatepass#readme","bugs":{"url":"https://github.com/akalsey/gatepass/issues"},"bin":{"gatepass":"bin/gatepass.js"},"dist":{"shasum":"7b95cbe62f2ccac6a3f9239a177a4987d96ba2eb","tarball":"https://registry.npmjs.org/@akalsey/gatepass/-/gatepass-0.1.1.tgz","fileCount":27,"integrity":"sha512-ai+rcMclkN6PNq5llzaxmM58tG58y7Ju6Kctzs6i4DB/s+VFgiaZ226tQsoqkZKS77J/3gL2E3mf/tfu0lLwMQ==","signatures":[{"sig":"MEUCIQDKU6140jXGJSVpib78Mp1+UFyadeZWjHIBkB8wg5iFbgIgTGznLVbT5wTgZbWMJ27W170JwU3jqxmMm3eGnxi9+T0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108257},"main":"src/cli.js","engines":{"node":">=18"},"gitHead":"4f9a6bdc714632d50e2ff40bdd3a10258eed8824","scripts":{"test":"node --test 'test/**/*.test.js'","start":"node bin/gatepass.js"},"_npmUser":{"name":"akalsey","email":"adam@kalsey.com"},"repository":{"url":"git+https://github.com/akalsey/gatepass.git","type":"git"},"_npmVersion":"11.13.0","description":"Conversational secrets management for OpenClaw agents","directories":{},"_nodeVersion":"26.3.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/gatepass_0.1.1_1782269636483_0.3455190300133062","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@akalsey/gatepass","version":"0.2.0","description":"Conversational secrets management for OpenClaw agents","keywords":["secrets","credentials","openclaw","agent","pass","gpg"],"license":"MIT","author":{"name":"Adam Kalsey"},"repository":{"type":"git","url":"git+https://github.com/akalsey/gatepass.git"},"bin":{"gatepass":"bin/gatepass.js"},"main":"src/cli.js","engines":{"node":">=18"},"scripts":{"start":"node bin/gatepass.js","test":"node --test 'test/**/*.test.js'"},"gitHead":"be57e699a6bc7f047b7937a3262d3d27cc82a274","_id":"@akalsey/gatepass@0.2.0","bugs":{"url":"https://github.com/akalsey/gatepass/issues"},"homepage":"https://github.com/akalsey/gatepass#readme","_nodeVersion":"26.3.1","_npmVersion":"11.13.0","dist":{"integrity":"sha512-1R/4G5nzAxTh412eQk0udsietLJVSU2Bgd001nSM53OraB0ZBKTx2UVwHfO0aYlF1r0xZGtqq1IERTfIfDnpDw==","shasum":"62cef3b56418634d031f363119f3733a9414d65a","tarball":"https://registry.npmjs.org/@akalsey/gatepass/-/gatepass-0.2.0.tgz","fileCount":28,"unpackedSize":110762,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCLaULT/M30HKeShggenZmao8SqZwP3T9OKW8vzCw1fTgIhAKxR92U4I6NYsHZ59G6CfodGMJQ2a38+ZQ0UeYhnsL9J"}]},"_npmUser":{"name":"akalsey","email":"adam@kalsey.com"},"directories":{},"maintainers":[{"name":"akalsey","email":"adam@kalsey.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gatepass_0.2.0_1783900673789_0.6421603645611758"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-19T17:08:55.641Z","modified":"2026-07-12T23:57:54.029Z","0.1.0":"2026-05-19T17:08:55.933Z","0.1.1":"2026-06-24T02:53:56.606Z","0.2.0":"2026-07-12T23:57:53.930Z"},"bugs":{"url":"https://github.com/akalsey/gatepass/issues"},"author":{"name":"Adam Kalsey"},"license":"MIT","homepage":"https://github.com/akalsey/gatepass#readme","keywords":["secrets","credentials","openclaw","agent","pass","gpg"],"repository":{"type":"git","url":"git+https://github.com/akalsey/gatepass.git"},"description":"Conversational secrets management for OpenClaw agents","maintainers":[{"name":"akalsey","email":"adam@kalsey.com"}],"readme":"# Gatepass\n\nConversational secrets management for OpenClaw agents.\n\nGatepass wraps `pass` and `gpg` into one opinionated command surface so an OpenClaw agent can retrieve credentials at the moment of use, without prompts. When the agent needs a credential it doesn't have, `gatepass get` exits with a structured error that tells the agent exactly what to ask the human to run — that's the conversational handoff.\n\n## Install\n\n```bash\nnpm install -g https://github.com/akalsey/Gatepass.git\n```\n\nRequires Node 18+, `gpg`, and `pass`. For TOTP support (`--otp` on `add` and `get`), install `oathtool` as well. Gatepass is not on the npm registry; install directly from GitHub.\n\n```bash\n# macOS\nbrew install gnupg pass oath-toolkit\n# Debian/Ubuntu\napt install gnupg pass oathtool\n# Fedora/RHEL\ndnf install gnupg2 pass oathtool\n```\n\n## Setup\n\nRun this on the bot host — the machine where the agent will run `gatepass get`:\n\n```bash\ngatepass setup\n```\n\nGenerates the bot GPG key, picks (or generates) your personal key, configures `gpg-agent` for unattended use, initializes the password store, and offers to install a boot-time unlock service. About two minutes.\n\nIf you plan to manage credentials directly on the bot (SSH in and run `gatepass add` there), that's all the setup you need. To run `gatepass add` from your workstation instead, see [Managing your keys remotely](#managing-your-keys-remotely) below.\n\nFor bot-only hosts, machines that already use GPG, or moving a bot key between machines, see [docs/host-migration.md](docs/host-migration.md).\n\n## Day-to-day\n\n```bash\ngatepass add metabase           # human stores a credential (interactive)\ngatepass get metabase           # agent retrieves it\ngatepass get --otp metabase     # agent gets a current TOTP code\ngatepass list                   # see what's stored\ngatepass remove metabase        # delete a credential\ngatepass doctor                 # diagnose runtime issues\ngatepass unlock                 # manually unlock the bot key\n```\n\n`gatepass add` is interactive only and prompts for the password with hidden input. Other fields can be supplied via flags or entered interactively:\n\n```bash\ngatepass add metabase \\\n  --user alice@example.com \\\n  --url https://metabase.example.com \\\n  --otp otpauth://totp/Metabase:alice?secret=ABCDEF... \\\n  --field account-id=4421\n```\n\n| Flag | Field |\n|---|---|\n| `-u`, `--user` | `user` |\n| `--url` | `url` |\n| `--email` | `email` |\n| `--otp` | `otp` (otpauth:// or base32) |\n| `--note` | `note` |\n| `-F`, `--field key=value` | arbitrary `key` |\n\nWhen you supply an `otp` key (via `--otp` or the interactive prompt), `gatepass add`\ngenerates a current TOTP code and asks you to enter it on the service before\nsaving. Most services require a working code to prove you have the OTP key\nbefore they enable two-factor authentication on the account, so the credential\nis only persisted if you confirm the code worked.\n\n### Getting a one-time password\n\n```bash\ngatepass get --otp metabase     # prints a fresh 6-digit TOTP code\n```\n\nThis decrypts the stored entry, runs its `otp` field through `oathtool`, and\nwrites the code to stdout (no other fields, no trailing metadata). Exits with\ncode 2 if the credential isn't stored, or if it's stored but has no `otp`\nfield — agents handle that the same way as a missing credential: ask the\nhuman to run `gatepass add <service> --otp <key>`.\n\n## Managing your keys remotely\n\nPrefer to run `gatepass add` from your workstation instead of SSH'ing into the bot? Pair the workstation with the bot host so both hold the bot key. Then credentials you add on the workstation are already encrypted to the bot — getting them onto the bot is just a file copy.\n\nTo pair, run `gatepass setup` on the bot first (above), then:\n\n1. Install gatepass, `gpg`, and `pass` on the workstation.\n2. On the bot, package the bot key into an encrypted bundle. You'll be prompted for a transit passphrase — type it twice:\n   ```bash\n   gatepass export --out gatepass-bot.gpg\n   ```\n3. Move `gatepass-bot.gpg` to your workstation. The bundle is encrypted, so any transport is fine (`scp`, USB stick, etc.).\n4. On the workstation, import the bundle. You'll be prompted for the transit passphrase from step 2:\n   ```bash\n   gatepass import gatepass-bot.gpg\n   ```\n5. Run `gatepass setup` on the workstation. It detects the imported bot key, picks (or generates) your personal key, and initializes a local password store with both keys as recipients.\n6. Shred the transit copy on both machines: `shred -u gatepass-bot.gpg`.\n\n`gatepass doctor` on each side confirms the pairing. For edge cases (existing personal keys, key rotations, container hosts), see [docs/host-migration.md](docs/host-migration.md).\n\n### Sync credentials to the bot host\n\n`gatepass add` writes encrypted entries into `~/.password-store/` on whatever machine you run it on. Once a workstation is paired to a bot host, getting credentials to the bot is just a file copy: every entry under `~/.password-store/` is already encrypted to the bot key, so it's safe over any transport. Land the files at `~/.password-store/` on the bot, preserving the directory layout — `bot/metabase.gpg` must stay under `bot/`, not get flattened to the root.\n\nSee [docs/syncing-credentials.md](docs/syncing-credentials.md) for rsync, scp, and Syncthing recipes.\n\n## Use it from an agent\n\nDrop the `secrets-management` skill into any OpenClaw agent (it lives at [`skills/secrets-management/`](./skills/secrets-management/)). The skill teaches the agent to call `gatepass get <service>`, parse the response (line 1 is the password; subsequent lines are `key: value`), and ask the human to run `gatepass add <service>` when a credential is missing (exit code 2).\n\n## More\n\n- [docs/troubleshooting.md](docs/troubleshooting.md) — install snags, locked bot key, sync issues\n- [docs/host-migration.md](docs/host-migration.md) — moving a bot key, pairing a workstation, `gatepass export` / `gatepass import`\n- [docs/syncing-credentials.md](docs/syncing-credentials.md) — rsync, scp, and Syncthing recipes for shipping the password store to the bot\n- [docs/personal-key-migration.md](docs/personal-key-migration.md) — moving a personal key\n- [docs/container.md](docs/container.md) — running gatepass in a container\n- [`skills/secrets-management/SKILL.md`](./skills/secrets-management/SKILL.md) — agent contract, exit codes\n- [`skills/secrets-management/setup.md`](./skills/secrets-management/setup.md) — environment variables, file format, boot-time unlock\n- [`skills/secrets-management/security.md`](./skills/secrets-management/security.md) — trust assumptions and threat model\n\n## License\n\nMIT\n","readmeFilename":"README.md"}