Rune is an open-source secrets manager built for developers who want full control. No cloud. No vendor lock-in. AES-GCM encryption with Argon2 key derivation — on your machine.
Every feature in Rune is deliberate. No bloat, no unnecessary abstractions. Just solid crypto and a great CLI.
Vault is powerful. AWS Secrets Manager is managed. Rune is the option that doesn't require a dedicated ops team or a monthly bill.
| Rune | HashiCorp Vault | AWS Secrets Manager | |
|---|---|---|---|
| Open source | ✓ MIT license | ◑ BSL 1.1 | ✗ Proprietary |
| Local-first | ✓ Fully offline | ◑ Self-hostable | ✗ Cloud only |
| Setup time | ✓ <2 minutes | ✗ Hours–days | ◑ ~30 minutes |
| Cost | ✓ Free | ◑ Free (self-host) | ✗ $0.40/secret/mo |
| Binary size | ✓ <8 MB | ✗ ~170 MB | ✗ N/A |
| CLI experience | ✓ First-class | ◑ Available | ◑ Via AWS CLI |
| Ops overhead | ✓ None | ✗ High | ◑ Medium |
| GUI | ✓ Native macOS app | ◑ Web UI | ◑ AWS Console |
Every workflow is one command. Pipe secrets, export .env, integrate with CI — Rune fits how developers actually work.
rune get secret into any script. Works with jq, xargs, and your whole shell ecosystem.rune run -- node server.jsrune export > .envrune completions bashA native macOS GUI for managing your secrets visually. Browse namespaces, create and rotate secrets, inspect access tokens — without leaving your Mac.
One command to install. Zero config to get started. Your first vault sealed in under two minutes.