You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I've used secretive happily for many years now and I'm very grateful for you sharing this with the rest of us.
It keeps me sane in the age of agentic workflows so I know that the access to remote servers or pushing to github can't happen without me approving that with the touch-id.
But more and more I'm hoping to solve couple of new things. This repository probably contains others who have similiar needs. I might be looking into totally wrong place and I might have totally wrong ideas but I would be very happy to hear from the community what you're thinking about.
I would personally want to give more and more access to agentic workflows but simultaneously being able to verify and manually allow things that might have deeply damaging consequences.
1. Improving observability for the secret usage
We could somehow share more information into the touch-id permission pop up.
I would want to know which command is asking for access to the key. Where are they trying to connect and which command are they running?
This would make it much more clearer if this is a push to my public github repo or getting access to a production server.
I have created separate SSH keys for production servers but I only have single Github key. In Github there are projects where I'm fine to allow claude code to push whatever it wants to the repo and there are other projects where mistakes from this would be devastating.
2. Add CLI access to secretive keys but also to Apple Passwords
I would also want to avoid using 3rd party services like 1password because Apple already has great Passwords.app. The only problem is that passwords.app doesn't have native CLI from apple.
If we are able to solve the observability issue above it would be great to integrate also programmatic access to the Passwords.app secrets through the same interface.
For example showing a popup:
./fetch-electric-bill.sh --date=$(date +"%Y-%m-%d") wants to access your credentials to electric-company.com with note 'Download the latest usage'.
Touch to allow access
This would then feel similiar as the 2FA my bank requires:
Do you want to confirm transfer to John Doe with bank account FI...123 with sum 123.45€
Press confirm here
Some commands like system update still require sudo access. I'm using the default integration with auth sufficient pam_tid.so but it doesn't provide great observability of what is going to happen next when I allow this:
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hey,
I've used secretive happily for many years now and I'm very grateful for you sharing this with the rest of us.
It keeps me sane in the age of agentic workflows so I know that the access to remote servers or pushing to github can't happen without me approving that with the touch-id.
But more and more I'm hoping to solve couple of new things. This repository probably contains others who have similiar needs. I might be looking into totally wrong place and I might have totally wrong ideas but I would be very happy to hear from the community what you're thinking about.
I would personally want to give more and more access to agentic workflows but simultaneously being able to verify and manually allow things that might have deeply damaging consequences.
1. Improving observability for the secret usage
We could somehow share more information into the touch-id permission pop up.
I would want to know which command is asking for access to the key. Where are they trying to connect and which command are they running?
This would make it much more clearer if this is a push to my public github repo or getting access to a production server.
I have created separate SSH keys for production servers but I only have single Github key. In Github there are projects where I'm fine to allow claude code to push whatever it wants to the repo and there are other projects where mistakes from this would be devastating.
2. Add CLI access to secretive keys but also to Apple Passwords
I would also want to avoid using 3rd party services like 1password because Apple already has great Passwords.app. The only problem is that passwords.app doesn't have native CLI from apple.
If we are able to solve the observability issue above it would be great to integrate also programmatic access to the Passwords.app secrets through the same interface.
For example showing a popup:
This would then feel similiar as the 2FA my bank requires:
There's already https://github.com/bendews/apw which shows how one can get access to passwords.app through the same route as chrome extension for icloud passwords: https://chromewebstore.google.com/detail/icloud-passwords/pejdijmoenmkgeppbflobdenhhabjlaj?hl=en&pli=1.
3. Integrating access to sudo
Some commands like system update still require sudo access. I'm using the default integration with
auth sufficient pam_tid.sobut it doesn't provide great observability of what is going to happen next when I allow this:All reactions