Vaults, and environments inside each: local, production, whatever you call them
Values hidden until you reveal one, on the phone, the web app and the terminal
Add, change, move and delete a secret from any of them
Import and export .env files, and cm secret run, stay on the command line (cm secret)
Never an assistant's: no MCP tool reaches a secret, whatever you allow
Add it to your cloud
$ cm quill add secrets
Or, as an administrator, open Administration → Quills in the app and choose Secrets. Either way your cloud shows you everything below and waits for your yes.
Standard. The installer offers Secrets when you set up a new cloud, so you may have it already. How installing works
What it adds to your cloud
Datamodels
The kinds of data it works with. Records belong to the people who write them, not to the quill: removing it leaves every one where it is.
A key and its value, in a vault and an environment. Sealed under the server's key; never an assistant's.
Vaultvaulttext, one linerequiredIndexed
Environmentenvironmenttext, one linerequiredIndexed
Keykeytext, one linerequiredIndexed
Valuevaluetext, one lineEncrypted
Lengthlengthwhole numberIndexed
Indexed fields are kept plain, so your cloud can sort and filter by them. Encrypted fields are encrypted before they reach the disk.
Screens
SecretsA list of secrets.
Each is a tab, drawn by your cloud itself on every surface:
Phonethe web app, made for the phone
Webthe full web app, in a browser
Terminalthe terminal app
Command linecm secrets
Assistanttools for your assistant, as you
Its own code
None. Everything it does is declared in quill.toml and run by your cloud itself.
In its own words
A Quill for Cloudmorrow: your
keys and passwords, in vaults (default, home, work) and in
environments inside each (local, production, whatever you call them),
on the phone, the web app and the terminal.
A value is never on screen until you ask: every surface draws it hidden,
and a tap, a click or a key reveals the one you want (and copies it, in the
terminal).
Add a key, change its value, move it to another vault or environment, or
delete it, from any surface.
Importing and exporting .env files, and cm secret run (a command with
an environment's secrets in its environment), stay on the command line:
they read and write files on your machine, which is where cm secret runs.
No assistant ever reaches a secret. The secret datamodel is refused to
every MCP tool, whatever else you let an assistant do.
The secrets themselves are part of Cloudmorrow's foundation, not this Quill:
they stay in the server's secrets store, sealed under the server's key, and
cm secret reaches them with or without it. This Quill is the screens.
What it adds to your Cloudmorrow
Datamodels
uses the foundational secret (domain Secrets), kept by the core's vaults backend
Screens
one list, picked through by vault and then environment, on the phone, the web app, the terminal and cm secrets; never to an assistant
Jobs
none
Datasets
none
Services, webhooks, APIs
none
It contains no code: everything above is declared in quill.toml.
Working on it
See CLAUDE.md. In short: cm quill check, then cm quill dev.