Install
Install the native binary with Homebrew:
brew install flakstad/kimen/kimen
kimen --version
You can also download the latest release. To build from source, install Kvist and run:
kvist build src/main.kvist
Five-minute setup
Start with a test or staging value while you learn the boundary.
1. Create the local encrypted vault
kimen vault init
2. Store one value
kimen secret set stripe_api_key
Kimen prompts for the secret without requiring it as a shell
argument. You can also pipe a value to
kimen secret set stripe_api_key --stdin.
3. Declare the requirement
Create .kimen/profiles/dev.kmap in the project:
env STRIPE_API_KEY=secret:stripe_api_key
4. Check and run
kimen map lint --profile dev --strict
kimen doctor --profile dev --strict
kimen plan --profile dev
kimen run --profile dev -- ./your-app
doctor and run open the vault and ask for its
passphrase unless a valid session or another unlock method is active.
map lint and plan inspect the contract without
opening the vault.
The application continues to read an ordinary
STRIPE_API_KEY environment variable. The plaintext value
does not need to live in the repository or a project-local
.env.
Current security boundary
Kimen encrypts values at rest and removes the need for plaintext secrets in the repository. It projects a value only when you invoke a runtime operation.
A process receiving a value through env, a file or stdin can read and copy it. Treat that process and its descendants as inside the secret boundary. If a coding agent controls the program's code, launching it with a production secret does not make the program trusted.
An active Kimen session stores unlock material in an owner-readable local file. That protects against other Unix users, but not against an unrestricted process running as you. Keep the vault locked while an untrusted same-user agent has broad shell access. Agent-aware unlock and client controls are product exploration, not guarantees in the current release.
Never paste a real secret into an issue, prompt, command argument or support request. Rotate a credential if you believe it has appeared in agent context or tool output.
Vault
The default vault is ~/.config/kimen/vault.kv. Use a
different vault explicitly:
kimen vault init --vault ~/.config/kimen/work.kv
kimen secret list --vault ~/.config/kimen/work.kv
Or select it for the current shell:
export KIMEN_VAULT=~/.config/kimen/work.kv
kimen secret list
Vault commands
kimen vault init
kimen vault path
kimen vault info
kimen vault rekey
kimen vault rekey --passphrase-cmd <cmd>
kimen vault rekey --dry-run
kimen vault rekey --backup-dir <path>
Secret commands
kimen secret set <name>
kimen secret set <name> --stdin
kimen secret list
kimen secret get <name> --unsafe-stdout
kimen secret rm <name>
kimen secret mv <from> <to>
--unsafe-stdout can place a plaintext value in terminal
output, logs or agent context. Use it only when that exposure is
intentional.
Read the complete vault, secret and session documentation for multiple vaults, session files, rekeying and non-interactive unlock.
Maps and profiles
Profiles are small .kmap files. Mapping values are vault
keys by default:
env NAME=secret:name
env DATABASE_URL=prod.database_url
env MODE=const:dev
file token.txt=secret:api_token
envpath TOKEN_FILE=token.txt
stdin secret:request_body
Prefix a value with const: for a literal,
secret: for an explicit vault key or
exec: to read stdout from a command.
Profile lookup
.kimen/profiles/<name>.kmap
$XDG_CONFIG_HOME/kimen/profiles/<name>.kmap
~/.config/kimen/profiles/<name>.kmap
Pass --profile <name> to use lookup, or
--map <path> for an explicit file.
kimen doctor validates the map, opens the vault and checks
that every referenced secret exists.
Read the complete profile and runtime projection documentation for lookup order, inline projections and every supported value source.
Projection modes
Run a trusted process
kimen run --env API_KEY=secret:api_key -- ./your-command
Render files
RUNTIME_DIR="$(mktemp -d -t kimen-runtime.XXXXXX)"
kimen render --dir "$RUNTIME_DIR" --file token.txt=secret:api_token
Rendered files contain plaintext. Choose a protected runtime
directory and remove it when the receiving program no longer needs
it. For systemd, Kimen can render under
/run/kimen/<service> with
--systemd-service <name>.
Generate an envfile
kimen envfile --out /protected/runtime/app.env \
--env API_KEY=secret:api_key
An envfile contains plaintext too. Kimen controls its creation, not the lifecycle or permissions of every consumer after it is written.
Inspect without values
kimen plan --profile dev
Sessions
A session avoids repeated passphrase prompts. It also widens the local boundary because a same-user process can read the session file.
kimen session start --ttl 30m
kimen session status
kimen session lock
Prefer a short TTL, lock the session when finished and do not leave it active while an untrusted same-user agent has unrestricted shell or filesystem access.
Command reference
kimen vault init|path|info|rekey
kimen secret set|list|get|rm|mv
kimen session start|status|lock|stop
kimen run [source] [projection...] -- <command>...
kimen render (--dir <path>|--systemd-service <name>) [source]
kimen envfile --out <path> [source]
kimen plan [source] [projection...]
kimen map lint (--profile <name>|--map <path>) [--strict]
kimen doctor (--profile <name>|--map <path>) [--strict]
A source is --profile <name> or
--map <path>. Projections are
--env NAME=value, --file path=value,
--envpath NAME=path or --stdin value.