v0.2.0 — public beta

secure secrets.
locally. simply.

Rune is an open-source secrets manager built for developers who want full control. No cloud. No vendor lock-in. AES-GCM encryption with Argon2 key derivation — on your machine.

$ curl -fsSL https://raw.githubusercontent.com/hyphen-ani/rune/main/scripts/install.sh | sh
# or: Homebrew Package Coming Soon
rune — zsh — 80×24

Built right

Everything you need.
Nothing you don't.

Every feature in Rune is deliberate. No bloat, no unnecessary abstractions. Just solid crypto and a great CLI.

Encryption-first
AES-256-GCM at rest. Keys derived with Argon2id — memory-hard, GPU-resistant. Your master password never leaves the machine.
AES-GCM · Argon2
Local-first
Vault lives on disk, fully under your control. No SaaS dependency, no telemetry, no mandatory cloud sync. Works fully offline.
Offline · Self-hosted
Token-based access
Issue short-lived, scoped access tokens. RBAC-ready from day one — grant read-only or write access per environment or team member.
RBAC · Scoped tokens
Sealed / Unsealed model
Vault stays sealed at rest. Unseal with master key to access secrets. Auto-seals on inactivity. Inspired by Vault — minus the ops burden.
Seal · Unseal
CLI-first UX
Every operation is one command. Pipe secrets into scripts, integrate CI/CD, export .env files. Built for how developers actually work.
Shell integration
Lightweight binary
Single binary under 8MB. Zero runtime dependencies. Starts in <50ms. No JVM, no Docker, no systemd unit required.
<8MB · Single binary

Comparison

Why Rune?

Vault is powerful. AWS Secrets Manager is managed. Rune is the option that doesn't require a dedicated ops team or a monthly bill.

Rune HashiCorp Vault AWS Secrets Manager
Open source✓ MIT license◑ BSL 1.1✗ Proprietary
Local-first✓ Fully offline◑ Self-hostable✗ Cloud only
Setup time✓ <2 minutes✗ Hours–days◑ ~30 minutes
Cost✓ Free◑ Free (self-host)✗ $0.40/secret/mo
Binary size✓ <8 MB✗ ~170 MB✗ N/A
CLI experience✓ First-class◑ Available◑ Via AWS CLI
Ops overhead✓ None✗ High◑ Medium
GUI✓ Native macOS app◑ Web UI◑ AWS Console

CLI Experience

Built for
the terminal.

Every workflow is one command. Pipe secrets, export .env, integrate with CI — Rune fits how developers actually work.

  • 01
    Composable commandsPipe rune get secret into any script. Works with jq, xargs, and your whole shell ecosystem.
  • 02
    Environment injectionRun any process with secrets as env vars: rune run -- node server.js
  • 03
    Export to .envGenerate a .env from any namespace: rune export > .env
  • 04
    Shell completionsFull autocomplete for bash, zsh, fish: rune completions bash
rune — zsh — 80×24

macOS Application

Rune Vault App.

A native macOS GUI for managing your secrets visually. Browse namespaces, create and rotate secrets, inspect access tokens — without leaving your Mac.

  • Secure storage with macOS Keychain integration
  • Visual namespace and environment browser
  • One-click secret rotation and expiry
  • Token management with permission scopes
  • Sealed/unsealed status at a glance
  • Native menu bar quick-access
Download for macOS
macOS 13+ · Apple Silicon & Intel · Free
Rune Vault — production
Workspaces
production
staging
development
Namespaces
api-keys
database
services
auth
production / api-keys
OPENAI_API_KEY
sk-••••••••••••••••••••••••wKJ9
active
STRIPE_SECRET_KEY
sk_live_••••••••••••••4rTm
active
SENDGRID_API_KEY
SG.••••••••••••••••••••••
rotated
GITHUB_TOKEN
ghp_••••••••••••••••••3xQp
active
DATADOG_API_KEY
••••••••••••••••••••••••••••
expires 7d
Vault unsealed · AES-256-GCM · 5 secrets
Get started

ship secrets safely.
today.

One command to install. Zero config to get started. Your first vault sealed in under two minutes.

$ Public Beta Coming Soon