Keyboard shortcuts

Press โ† or โ†’ to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

What is Sesam?

sesam is a tool for managing secrets in git.

Three words, each of them doing some work:

  • secrets: Are just regular files that contain something precious to you. They are on your filesystem revealed (decrypted) and sealed (encrypted).
  • managing: Making sure sealed and revealed are in sync and allow the user to define who has access to what secret.
  • in git: Developers are naturally used to git and sesam integrates well with it.

Intro

Software projects often need to store and load several secrets such as database passwords, certificates, API keys or other credentials. Those secrets should be stored encrypted and only be accessible to the users that actually need them.

sesam allows leveled access with multiple users to those encrypted secrets and gives you a simple interface to manage both users and secrets.

In short, sesam fits well the GitOps model of infrastructure.

Note

The term user does not necessarily refer to a person. A user can also be a machine, like a server where sesam is installed.

What is a secret manager?

You might think of a password manager now, which is not too far off - sesam can indeed also be used as a password manager. A password manager is usually targeted at managing individual secrets, while a secret manager is focused on sharing selected secrets with other users in a team and machines. If you already know what a secret manager is then you might be interested in Why we built another tool.

Features

Security

  • Every write is recorded, signed and verified by an audit log.
  • Support for SSH keys, age keys and age plugin identities.
  • Different access levels through user groups.
  • Encrypted at rest; only secret paths and group membership are visible in the repo.
  • Safe to use (hard to accidentally push unencrypted secrets)
  • Per-secret integrity checks with root-hash verification.

Convenience

  • Forge recipient shortcuts for GitHub, GitLab and Codeberg.
  • Both declarative (config) and imperative (CLI) workflows possible.
  • Familiarity to git users.
  • Decentralized & offline ready.
  • Scriptable via CLI interface.
  • Somewhat fast encryption and decryption.ยน
  • Almost zero dependencies.
ยน somewhat fast is the new ๐Ÿš€ blazingly fast ๐Ÿš€ - benchmarks will follow later.

Git Integration

  • Secrets are naturally versioned.
  • Allows viewing local diffs of secrets and the audit log.
  • Hooks keep revealed files in sync on checkout, pull and merge.
  • Merging of secrets is supported.

Planned features

  • Support for rotation and swapping of secrets (Plan)
  • More tooling so that sesam can be well used as password manager.
  • Deeper support for env files.

Who is it for?

  • Open source developers wanting to store secrets in their repos and give only their co-developers access.
  • Small to mid-sized teams wanting to have different access levels in their secrets.
  • Individuals wanting to store secrets in their git repos, even if it's just a single user.
  • Machine users that need a scriptable tool.

Learning

How to use this manual:

The name

It is a reference to Ali Baba and the Forty Thieves out of the story collection One Thousand and One Nights. In this story the cave opens upon calling the passphrase "Open, Sesam!" revealing a hidden cave full of gold and treasures.

You see this scene depicted on the landing page.

The logo is a sesame pod, with the seeds replaced by cute little keys.

Built 2026-09-14 15:59:06 โ€ข commit: 2d65cfb