Tswap–Yubikey-backed secret injection for IaC and AI-assisted workflows
Tswap–Yubikey-backed secret injection for IaC and AI-assisted workflows
I built tswap after noticing that Claude Code, while genuinely useful for managing a Kubernetes cluster, was pulling plaintext secrets from every manifest it touched. I wanted the AI to be able to do its job without ever seeing the actual values. tswap keeps secrets in an AES-encrypted vault file on disk. The decryption key is derived from a YubiKey via HMAC challenge-response. At init you pair two YubiKeys — either unlocks the vault, so you have no single point of hardware failure. Config files use a comment-based placeholder that keeps them valid YAML: stringData: DB_PASSWORD: # tswap: db-password Deployment is a pipe: tswap apply values.yaml | helm upgrade myapp ./chart -f - The privilege split is the key design decision: `apply`, `run`, and `check` need no elevation (AI agent gets these). `get`, `list`, `delete`, and `export` require sudo/admin (human gets these). The AI can deploy; it can't read or enumerate secrets. Other features: burn tracking for rotation, `redact` for stripping values from logs, `check` for pre-deploy validation, `export`/`import` for vault migration. Single binary, no daemon. Tested on Linux, macOS, and Windows. https://github.com/stevedcc/TokenSwap
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
AI-Assisted Scratchpad
Traceable AI-assisted manuscript review for researchers
Traceable AI-assisted manuscript review for researchers
Chunavilal – An AI Assisted Election Result Analysis App
AI-assisted legal triage for illegal occupation in Spain
AI-assisted legal triage for illegal occupation in Spain
DAAF – Reproducible AI-assisted data analysis for researchers
AI assisted freelance
Kbsecret – A secret manager backed by Keybase and KBFS
ScriptLoom – AI-assisted screenwriting with drafting and voice edits