fnox set
- Usage:
fnox set [FLAGS] <KEY> [VALUE] - Aliases:
s
Set a secret value
Arguments
<KEY>— Secret key (environment variable name)[VALUE]— Secret value to store.If omitted: reads from stdin when piped (
echo "x" | fnox set KEY), or prompts interactively with hidden input.Passing secrets as arguments exposes them in shell history and
psoutput. For sensitive values, prefer stdin or the interactive prompt.
Flags
-d --description <DESCRIPTION>— Description of the secret-g --global— Save to the global config file (~/.config/fnox/config.toml)-k --key-name <KEY_NAME>— Key name in the provider (if different from env var name)-n --dry-run— Show what would be done without making changes-p --provider <PROVIDER>— Provider to store the secret in (defaults to its existing provider, then default_provider)--base64-encode— Base64 encode the secret--default <DEFAULT>— Default value to use if secret is not found--from-file <FROM_FILE>— Read the secret value verbatim from a UTF-8 file--if-missing <IF_MISSING>— What to do if the secret is missing (error, warn, ignore)Choices:
error,warn,ignore-h --help— Print help
Examples
Configure a provider first. Omitting VALUE prompts with hidden input in a terminal or reads piped stdin. Without a selected provider, set writes a plaintext default. --from-file preserves file contents, including trailing newlines.
fnox set DATABASE_URL --provider age
fnox set SSH_PRIVATE_KEY --provider age --from-file ~/.ssh/id_ed25519
fnox set DATABASE_URL --profile staging --provider ageRelated
- Quick start
- File secrets
- Global options, including profile selection and non-interactive mode.