Multiple Provider Support
Works with age, AWS KMS/SM, Azure, GCP, 1Password, Bitwarden, Bitwarden Secrets Manager, Infisical, password-store, HashiCorp Vault, and more.
Manage secrets with encryption or cloud providers - or both!
# Initialize fnox in your project
fnox init
# Set a secret (stores it encrypted in fnox.toml)
fnox set DATABASE_URL "postgresql://localhost/mydb"
# Get a secret
fnox get DATABASE_URL
# Run commands with secrets loaded as env vars
fnox exec -- npm start
# Enable shell integration (auto-load secrets on cd)
eval "$(fnox activate bash)" # or zsh, fish โ see docs for NushellThe recommended setup: keep secrets in a vault like 1Password, commit only references to them in fnox.toml, and cache them locally with fnox sync under a personal age key โ which can even live in hardware like a Secure Enclave, YubiKey, or TPM.
fnox sync --provider sync-age --local-fileThe vault stays the source of truth, but secrets load instantly and offline on every cd. See The Golden Path for details, or jump straight to the setup walkthrough.
fnox uses a simple TOML config file (fnox.toml) that you check into git. Secrets are either:
You configure providers (encryption methods or cloud services), then assign each secret to a provider. fnox handles the rest.
# fnox.toml
[providers]
age = { type = "age", recipients = ["age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p"] }
[secrets]
DATABASE_URL = { provider = "age", value = "YWdlLWVuY3J5cHRpb24uLi4=" } # โ encrypted ciphertext, safe to commit
API_KEY = { default = "dev-key-12345" } # โ plain default value for local devfnox works with over 20 providers across four categories:
See the Providers Overview for the full list and a comparison of trade-offs.