Skip to content
Back to skills

Secret Portal

ASecurity

Spin up a one-time web UI for securely entering secret keys and env vars. Supports guided instructions, single-key mode, and cloudflared tunneling.

  • 33 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
securitygobashgitapisecurity

Works with

  • terminal
  • cli
  • api

Security analysis

A100/100

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill secret-portal --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Secret Portal?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Secret Portal
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-secret-portal/badge)](https://www.skillsdirectory.com/skills/dvcrn-secret-portal)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: secret-portal
description: "Spin up a one-time web UI for securely entering secret keys and env vars. Supports guided instructions, single-key mode, and cloudflared tunneling."
---

# Secret Portal

Spin up a temporary, one-time-use web UI for securely entering secret keys and environment variables. No secrets ever touch chat history or terminal logs.

## Quick Start

```bash
# Single key with cloudflared tunnel (recommended)
uv run --with secret-portal secret-portal \
  -k API_KEY_NAME \
  -f ~/.secrets/target-env-file \
  --tunnel cloudflared

# With guided instructions and a link to the key's console
uv run --with secret-portal secret-portal \
  -k OPENAI_API_KEY \
  -f ~/.env \
  -i '<strong>Get your key:</strong><ol><li>Go to platform.openai.com</li><li>Click API Keys</li><li>Create new key</li></ol>' \
  -l "https://platform.openai.com/api-keys" \
  --link-text "Open OpenAI dashboard →" \
  --tunnel cloudflared

# Multi-key mode (no -k flag, user enters key names and values)
uv run --with secret-portal secret-portal \
  -f ~/.secrets/keys.env \
  --tunnel cloudflared
```

## Options

| Flag | Description |
|------|-------------|
| `-k, --key` | Pre-populate a single key name (user only enters the value) |
| `-f, --env-file` | Path to save secrets to (default: `~/.env`) |
| `-i, --instructions` | HTML instructions shown above the input field |
| `-l, --link` | URL button for where to get/create the key |
| `--link-text` | Label for the link button (default: "Open console →") |
| `--tunnel` | `cloudflared` (recommended), `ngrok`, or `none` |
| `-p, --port` | Port to bind to (default: random) |
| `--timeout` | Seconds before auto-shutdown (default: 300) |

## Tunneling

**Use `--tunnel cloudflared`** — it's free, requires no account, has no interstitial pages, provides HTTPS, and auto-downloads the binary if missing.

ngrok free tier shows an interstitial warning page that blocks mobile and automated use.

Without a tunnel, the port must be open in your firewall/security group. The CLI will warn you if it detects the port is unreachable.

## Security

- One-time use: portal expires after a single submission
- Token auth: URL contains a random 32-byte token
- Secret values are **never** printed to stdout/stderr (enforced by tests)
- Env file is written with `600` permissions (owner-only)
- Secrets never touch chat history or terminal logs

## Source

https://github.com/Olafs-World/secret-portal

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…