Secret management you can self-host.
Sotto is Apache-2.0 and ships as one compose file: the sync server, Postgres, and Caddy for HTTPS. Your devices hold the keys; the box only ever sees ciphertext.
Your box in three moves
- Start the box. Point DNS at a machine, fill in a handful of variables, and bring the stack up. The deploy runbook walks through each one.
- Log in against your own server. Point the CLI and the web vault at your origin. Same app, same flow, your infrastructure.
- Keep it yours. Backups run from one script, and the anonymous version ping switches off with
SOTTO_TELEMETRY=off.
$ curl https://secrets.example.com/health
okQuestions, answered
What leaves my box?
By default, one anonymous version ping a day. Set SOTTO_TELEMETRY=off to stop even that.
What do I need?
A box with Docker, a domain with DNS pointed at it, and a GitHub OAuth app for logins. The deploy runbook covers all three.
Who can read my secrets?
Only devices holding a grant. The server enforces the grant graph but stores ciphertext it cannot decrypt.
Your box, your ciphertext
Apache-2.0, free forever. Self-hosting has no tiers.