kimen

Use Kimen.

Install Kimen, complete the first local workflow and look up the commands and configuration forms the product supports.

Install

Install the native binary with Homebrew:

brew install flakstad/kimen/kimen
kimen --version

You can also download the latest release. To build from source, install Kvist and run:

kvist build src/main.kvist

Five-minute setup

Start with a test or staging value while you learn the boundary.

1. Create the local encrypted vault

kimen vault init

2. Store one value

kimen secret set stripe_api_key

Kimen prompts for the secret without requiring it as a shell argument. You can also pipe a value to kimen secret set stripe_api_key --stdin.

3. Declare the requirement

Create .kimen/profiles/dev.kmap in the project:

env STRIPE_API_KEY=secret:stripe_api_key

4. Check and run

kimen map lint --profile dev --strict
kimen doctor --profile dev --strict
kimen plan --profile dev
kimen run --profile dev -- ./your-app

doctor and run open the vault and ask for its passphrase unless a valid session or another unlock method is active. map lint and plan inspect the contract without opening the vault.

The application continues to read an ordinary STRIPE_API_KEY environment variable. The plaintext value does not need to live in the repository or a project-local .env.

Current security boundary

Kimen encrypts values at rest and removes the need for plaintext secrets in the repository. It projects a value only when you invoke a runtime operation.

A process receiving a value through env, a file or stdin can read and copy it. Treat that process and its descendants as inside the secret boundary. If a coding agent controls the program's code, launching it with a production secret does not make the program trusted.

An active Kimen session stores unlock material in an owner-readable local file. That protects against other Unix users, but not against an unrestricted process running as you. Keep the vault locked while an untrusted same-user agent has broad shell access. Agent-aware unlock and client controls are product exploration, not guarantees in the current release.

Never paste a real secret into an issue, prompt, command argument or support request. Rotate a credential if you believe it has appeared in agent context or tool output.

Vault

The default vault is ~/.config/kimen/vault.kv. Use a different vault explicitly:

kimen vault init --vault ~/.config/kimen/work.kv
kimen secret list --vault ~/.config/kimen/work.kv

Or select it for the current shell:

export KIMEN_VAULT=~/.config/kimen/work.kv
kimen secret list

Vault commands

kimen vault init
kimen vault path
kimen vault info
kimen vault rekey
kimen vault rekey --passphrase-cmd <cmd>
kimen vault rekey --dry-run
kimen vault rekey --backup-dir <path>

Secret commands

kimen secret set <name>
kimen secret set <name> --stdin
kimen secret list
kimen secret get <name> --unsafe-stdout
kimen secret rm <name>
kimen secret mv <from> <to>

--unsafe-stdout can place a plaintext value in terminal output, logs or agent context. Use it only when that exposure is intentional.

Read the complete vault, secret and session documentation for multiple vaults, session files, rekeying and non-interactive unlock.

Maps and profiles

Profiles are small .kmap files. Mapping values are vault keys by default:

env NAME=secret:name
env DATABASE_URL=prod.database_url
env MODE=const:dev
file token.txt=secret:api_token
envpath TOKEN_FILE=token.txt
stdin secret:request_body

Prefix a value with const: for a literal, secret: for an explicit vault key or exec: to read stdout from a command.

Profile lookup

.kimen/profiles/<name>.kmap
$XDG_CONFIG_HOME/kimen/profiles/<name>.kmap
~/.config/kimen/profiles/<name>.kmap

Pass --profile <name> to use lookup, or --map <path> for an explicit file. kimen doctor validates the map, opens the vault and checks that every referenced secret exists.

Read the complete profile and runtime projection documentation for lookup order, inline projections and every supported value source.

Projection modes

Run a trusted process

kimen run --env API_KEY=secret:api_key -- ./your-command

Render files

RUNTIME_DIR="$(mktemp -d -t kimen-runtime.XXXXXX)"
kimen render --dir "$RUNTIME_DIR" --file token.txt=secret:api_token

Rendered files contain plaintext. Choose a protected runtime directory and remove it when the receiving program no longer needs it. For systemd, Kimen can render under /run/kimen/<service> with --systemd-service <name>.

Generate an envfile

kimen envfile --out /protected/runtime/app.env \
  --env API_KEY=secret:api_key

An envfile contains plaintext too. Kimen controls its creation, not the lifecycle or permissions of every consumer after it is written.

Inspect without values

kimen plan --profile dev

Sessions

A session avoids repeated passphrase prompts. It also widens the local boundary because a same-user process can read the session file.

kimen session start --ttl 30m
kimen session status
kimen session lock

Prefer a short TTL, lock the session when finished and do not leave it active while an untrusted same-user agent has unrestricted shell or filesystem access.

Command reference

kimen vault init|path|info|rekey
kimen secret set|list|get|rm|mv
kimen session start|status|lock|stop
kimen run [source] [projection...] -- <command>...
kimen render (--dir <path>|--systemd-service <name>) [source]
kimen envfile --out <path> [source]
kimen plan [source] [projection...]
kimen map lint (--profile <name>|--map <path>) [--strict]
kimen doctor (--profile <name>|--map <path>) [--strict]

A source is --profile <name> or --map <path>. Projections are --env NAME=value, --file path=value, --envpath NAME=path or --stdin value.