Local-first, age-encrypted secret manager for the terminal. Use when an agent needs to store, read, generate, search, rotate, or inject secrets — API tokens, SSH/DB passphrases, TOTP seeds, or whole credential files — from the command line. Fully non-interactive and scriptable: export KS_PASSPHRASE and pass --json for a single machine-readable JSON object per command.
2026-06-01