Skip to main content
SDK-only projects can use @fentaris/core and the local fentaris auth and fentaris secrets commands without creating fentaris.json. The CLI discovers the nearest package.json that depends on @fentaris/core.

Quick Start

Install the core package and CLI:
Add Fentaris metadata to package.json:
Declare the credential reference and its encrypted local source in the entrypoint:
Generate the committed manifest:
Store local values without putting them in shell history:
The reference explicitly resolves through the project vault. On macOS, Keychain normally supplies its unlock key; other platforms/CI require an explicit unlock mechanism. Source bindings can use the existing environment without copying values. Read Project vault and client keys for isolation, sources, and recovery.

Manage Client API Keys

Configure identity: { strategy: projectVaultIdentityStrategy({root: process.cwd()}), required: true } and retain your existing policy and incoming user declarations. Then create and inspect named keys:
Creation delivers a sensitive raw value once. Only a verifier hash is stored. Revoked/expired keys fail authentication. Incoming user IDs remain distinct from upstream account aliases.

What To Commit

Commit the manifest and the package metadata:
Do not commit the encrypted local credential store:
.fentaris/secrets.manifest.json contains reference names and scopes only. It is the schema teammates and CI need; it does not contain secret values.

Validate In CI

Use manifest check mode to catch stale credential declarations:
Run fentaris secrets doctor locally when a teammate cannot start the proxy because a required credential is missing.