Sotto

Secret management you can self-host.

Sotto is Apache-2.0 and ships as one compose file: the sync server, Postgres, and Caddy for HTTPS. Your devices hold the keys; the box only ever sees ciphertext.

Your box in three moves

  1. Start the box. Point DNS at a machine, fill in a handful of variables, and bring the stack up. The deploy runbook walks through each one.
  2. Log in against your own server. Point the CLI and the web vault at your origin. Same app, same flow, your infrastructure.
  3. Keep it yours. Backups run from one script, and the anonymous version ping switches off with SOTTO_TELEMETRY=off.
$ curl https://secrets.example.com/health
ok

Questions, answered

What leaves my box?

By default, one anonymous version ping a day. Set SOTTO_TELEMETRY=off to stop even that.

What do I need?

A box with Docker, a domain with DNS pointed at it, and a GitHub OAuth app for logins. The deploy runbook covers all three.

Who can read my secrets?

Only devices holding a grant. The server enforces the grant graph but stores ciphertext it cannot decrypt.

Your box, your ciphertext

Apache-2.0, free forever. Self-hosting has no tiers.