Skip to content

v1.1.2

Choose a tag to compare

@github-actions github-actions released this 22 Mar 11:19
· 93 commits to main since this release

AgentSecrets v1.1.2

What's New

Environment Support

Every project now has three built-in environments: development, staging, and production. The active environment determines which secrets the proxy resolves, which cloud blobs are synced, and which .env file is read or written. One command switches the context and everything downstream adjusts automatically.

agentsecrets environment switch production
agentsecrets status
# Environment: production

Secrets are scoped per environment. The same key name can hold different values in different environments and they never bleed into each other.

agentsecrets environment list
#   development   12 secrets   ← active
#   staging        8 secrets
#   production    12 secrets

Copy an environment to bootstrap a new one with the same values:

agentsecrets environment copy development staging

Or merge from one environment into another, prompting for new values per key — useful when moving from staging to production where the values must be different:

agentsecrets environment merge staging production

The secrets list now shows cross-environment coverage so missing keys are visible immediately without switching context:

KEY             DEV   STAGING   PROD
STRIPE_KEY       ✓       ✓        ✓
OPENAI_KEY       ✓       ✓        ✗   ← missing in production
DATABASE_URL     ✓       ✗        ✗   ← missing in staging and production

Push and pull are environment-aware. agentsecrets secrets pull in production writes to .env.production. agentsecrets secrets push reads from .env.{active_environment} first and falls back to .env. Cross-environment diff is also supported:

agentsecrets secrets diff --from development --to production

The audit log records the active environment on every entry. Proxy logs can be filtered by environment:

agentsecrets proxy logs --env production

agentsecrets status shows the active environment at all times. Environment is per-directory — .agentsecrets/project.json pins the environment for each project so multiple terminal windows in different projects never conflict. AGENTSECRETS_ENV overrides everything for CI/CD pipelines.

Development is the default. Existing secrets are automatically in the development environment with no action required.


Per-Project Storage Mode

Storage mode — whether a project uses keychain-only storage or keychain plus .env files — is now set per project rather than globally.

On first-time setup, agentsecrets init asks which storage mode you want. That preference is stored as your global default for future projects. When you initialise a new project on the same machine, the global default is applied silently. To override it for a specific project, pass the flag:

agentsecrets init --storage-mode 2

The storage mode is written to .agentsecrets/project.json and is permanent for that project regardless of what the global default is or becomes later. An agent-managed project initialised with --storage-mode 1 stays keychain-only even if the developer later changes their global default to mode 2.

The AgentSecrets skill for OpenClaw always initialises with --storage-mode 1. Agent-managed projects are always keychain-only.


Update Notifications

AgentSecrets now checks for new releases in the background and prints a notice when a newer version is available. The check runs at most once per 24 hours, times out silently after 2 seconds if the network is unavailable, and shows the correct upgrade command for how the binary was installed.

╭─────────────────────────────────────────────────────╮
│  Update available: v1.1.1 → v1.1.2                  │
│  Run: brew upgrade The-17/tap/agentsecrets           │
│  Changelog: github.com/The-17/agentsecrets/releases  │
╰─────────────────────────────────────────────────────╯

The notice prints after command output and never interrupts the result. It is automatically suppressed when stdout is not a TTY so scripts and piped output are not affected. To disable it permanently:


Full Changelog

  • Added agentsecrets environment switch/list/copy/merge/clean commands
  • Added environment field to .agentsecrets/project.json and global config
  • Added cross-environment coverage table to agentsecrets secrets list
  • Added --from and --to flags to agentsecrets secrets diff
  • Added --env filter to agentsecrets proxy logs
  • Added environment field to audit log entries
  • Added environment-aware push and pull for storage mode 2
  • Added .env.example generation on every pull
  • Added storage mode to .agentsecrets/project.json
  • Added storage mode prompt to first-time agentsecrets init
  • Added --storage-mode flag to agentsecrets init
  • Added background update check with 24-hour cache
  • Added agentsecrets config set update-check false to disable notifications
  • Updated agentsecrets status to show active environment

Built by [The Seventeen](https://theseventeen.co)