Project overview
zKettle encrypts secrets locally and stores only ciphertext, placing the decryption key in the URL fragment so the server never receives it. Links can expire by time or view count and can be revoked early, with CLI and MCP tools for common workflows. Reading through a terminal or agent can expose plaintext to logs or context, so file or clipboard output is safer.
Repository facts
- Primary language
- Go
- License
- AGPL-3.0
- Repository updated
- Mar 3, 2026
- Default branch
- main
Resource types
CLI appMCP server
Use cases
Security and privacy
Platforms
Claude Code
Runtime
Command lineDockerLocalSelf-hosted
Protocols & integrations
Model Context Protocol
Capabilities
Tool use