Versions:
keyforge is a secrets generation and management utility published by Joshua, currently at version 0.2.0 with one released version listed in the catalog. Falling into the security and credential-management category, it generates cryptographically strong secrets and stores them in a locally searchable vault sealed with Windows DPAPI under the user's login. Distributed as a single binary with no runtime dependencies, it makes no network calls, installs to the user profile, and requires no administrator rights. All generated values are drawn from the operating system CSPRNG using rejection sampling rather than modulo reduction, ensuring uniform character distribution, and each generator reports the entropy it produced. Generation capabilities include random strings and API keys over a chosen alphabet, passwords with character-class requirements, EFF diceware passphrases, structured identifiers such as UUIDv4, UUIDv7, ULID, nanoid, and TOTP seeds, and keypairs covering ed25519, RSA, and age identities. Secrets issued externally can also be stored by pasting them in, with the tool transparently noting that it can only estimate the strength of values it did not generate. This makes it suitable for developer workflows such as provisioning API credentials, rotating passwords, creating signing keys, and centralizing third-party tokens. Any stored secret can be rolled so that the replacement value takes over while the name, creation date, and tags remain unchanged, with the outgoing value retained until the cutover is complete; an optional per-key interval flags secrets overdue for rotation. Retrieval relies on fuzzy search across names, tags, and kinds, never over the secret material itself. Interaction is available either through a full-screen interface launched by running `keys` with no arguments or through subcommands intended for scripting, supporting both interactive browsing and automation use cases on Windows systems.
Tags: