v1.1.2
AgentSecrets v1.1.2
What's New
Environment Support
Every project now has three built-in environments: development, staging, and production. The active environment determines which secrets the proxy resolves, which cloud blobs are synced, and which .env file is read or written. One command switches the context and everything downstream adjusts automatically.
agentsecrets environment switch production
agentsecrets status
# Environment: productionSecrets are scoped per environment. The same key name can hold different values in different environments and they never bleed into each other.
agentsecrets environment list
# development 12 secrets ← active
# staging 8 secrets
# production 12 secretsCopy an environment to bootstrap a new one with the same values:
agentsecrets environment copy development stagingOr merge from one environment into another, prompting for new values per key — useful when moving from staging to production where the values must be different:
agentsecrets environment merge staging productionThe secrets list now shows cross-environment coverage so missing keys are visible immediately without switching context:
KEY DEV STAGING PROD
STRIPE_KEY ✓ ✓ ✓
OPENAI_KEY ✓ ✓ ✗ ← missing in production
DATABASE_URL ✓ ✗ ✗ ← missing in staging and production
Push and pull are environment-aware. agentsecrets secrets pull in production writes to .env.production. agentsecrets secrets push reads from .env.{active_environment} first and falls back to .env. Cross-environment diff is also supported:
agentsecrets secrets diff --from development --to productionThe audit log records the active environment on every entry. Proxy logs can be filtered by environment:
agentsecrets proxy logs --env productionagentsecrets status shows the active environment at all times. Environment is per-directory — .agentsecrets/project.json pins the environment for each project so multiple terminal windows in different projects never conflict. AGENTSECRETS_ENV overrides everything for CI/CD pipelines.
Development is the default. Existing secrets are automatically in the development environment with no action required.
Per-Project Storage Mode
Storage mode — whether a project uses keychain-only storage or keychain plus .env files — is now set per project rather than globally.
On first-time setup, agentsecrets init asks which storage mode you want. That preference is stored as your global default for future projects. When you initialise a new project on the same machine, the global default is applied silently. To override it for a specific project, pass the flag:
agentsecrets init --storage-mode 2The storage mode is written to .agentsecrets/project.json and is permanent for that project regardless of what the global default is or becomes later. An agent-managed project initialised with --storage-mode 1 stays keychain-only even if the developer later changes their global default to mode 2.
The AgentSecrets skill for OpenClaw always initialises with --storage-mode 1. Agent-managed projects are always keychain-only.
Update Notifications
AgentSecrets now checks for new releases in the background and prints a notice when a newer version is available. The check runs at most once per 24 hours, times out silently after 2 seconds if the network is unavailable, and shows the correct upgrade command for how the binary was installed.
╭─────────────────────────────────────────────────────╮
│ Update available: v1.1.1 → v1.1.2 │
│ Run: brew upgrade The-17/tap/agentsecrets │
│ Changelog: github.com/The-17/agentsecrets/releases │
╰─────────────────────────────────────────────────────╯
The notice prints after command output and never interrupts the result. It is automatically suppressed when stdout is not a TTY so scripts and piped output are not affected. To disable it permanently:
Full Changelog
- Added
agentsecrets environment switch/list/copy/merge/cleancommands - Added environment field to
.agentsecrets/project.jsonand global config - Added cross-environment coverage table to
agentsecrets secrets list - Added
--fromand--toflags toagentsecrets secrets diff - Added
--envfilter toagentsecrets proxy logs - Added environment field to audit log entries
- Added environment-aware push and pull for storage mode 2
- Added
.env.examplegeneration on every pull - Added storage mode to
.agentsecrets/project.json - Added storage mode prompt to first-time
agentsecrets init - Added
--storage-modeflag toagentsecrets init - Added background update check with 24-hour cache
- Added
agentsecrets config set update-check falseto disable notifications - Updated
agentsecrets statusto show active environment
Built by [The Seventeen](https://theseventeen.co)