Share API keys without pasting them into chat.
An API key in chat is a leak with extra steps. Store keys in Sotto, share them with the teammates who need them, and rotate them in one place when they leak.
Keys in, leaks out
- Store the key once.
sotto settakes the value through a hidden prompt, so it never lands in your shell history. - Share it two ways. Grant an environment to a teammate for ongoing access, or send a one-time link for a single handover.
- Rotate in one place. Revoke the old key at the provider, set the new one, and push. Teammates get it on their next pull, and CI on its next run.
$ sotto set STRIPE_SECRET_KEY
Value:
set STRIPE_SECRET_KEY (acme-api/dev)
$ sotto share STRIPE_SECRET_KEY
share link (acme-api/dev) - burns after 1 view(s):
https://getsotto.co.uk/s/9fK2xQ#k=Vq3TzEjm…Questions, answered
What is the difference between a grant and a link?
A grant gives a teammate ongoing access to an environment. A link hands one secret to one reader, once, then burns.
How does CI get secrets?
Hand CI a scoped machine token (SOTTO_TOKEN) instead of the key itself. Revoke the token and CI loses access without touching the key.
Someone pasted a key in chat. Now what?
Rotate it: revoke the old key at the provider, set the new value, and push. Teammates get it on their next pull. Then delete the message.
Keys change. Chat is forever.
Free for personal use, and for teams of up to three sharing one project.