author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345579 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345572 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345563 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345551 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345540 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345533 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345529 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345522 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345503 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345496 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345489 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345357 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345061 +0100 parent 10a292bca563efbe5972d7ffc33ee4b96a868e42 author Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1709970985 +0100 committer Daniel Hougaard <62331820+DanielHougaard@users.noreply.github.com> 1710345029 +0100 Feat: Org Scoped JWT Tokens Add link button Fix: Avoid invalidating all queries on logout to prevent UI glitch Update _app.tsx Feat: Scoped JWT to organization, add authMethod to request Feat: Scoped JWT to organization, Add authMethod to services Feat: Scoped JWT to organization, require organization on all requests by default on JWT requests Update index.ts Feat: Scoped JWT to organization Chore: Move SAML org check to permission service Feat: Scoped JWT to organization, actorAuthMethod to create project DTO Fix: Invalidate after selecting organization Chore: Optional 'invalidate' option for create org hook Fix: Creating dummy workspaces Fix: Select org after creation Feat: Org Scoped JWT's, remove inline service Fix: ActorType unresolved Fix: Better type checking Feat: Org scoped JWT's Fix: Add missing actor org ID Fix: Add missing actor org ID Fix: Return access token Update auth-type.ts Fix: Add actor org ID Chore: Remove unused code Fix: Add missing actor org ID to permission check Fix: Add missing actor auth method to permission checks Fix: Include actor org id Chore: Remove redundant lint comment Fix: Add missing actorOrgId to service handlers Fix: Rebase fixes Fix: Rebase LDAP fixes Chore: Export Cli login interface Update queries.tsx Feat: Org scoped JWT's CLI support Update inject-permission.ts Fix: MFA Remove log Fix: Admin signup, select organization Improvement: Use select organization hook Update permission-service.ts Fix: Make API keys compatible with old endpoints Update inject-permission.ts Chore: Better error messages Update index.ts Fix: Signup not redirecting to backup PDF page due to error Select org on signup Type improvements Chore: Removed code that spans out of scope Fix: Better types Chore: Move comment Chore: Change order Fix: Code readability Fix: Code readability Update auth-token-service.ts Chore: Remove old comments Fix: Cleanup Chore: Minor code cleanup Fix: Add auth method and organization ID to test JWT Fix: Get org ID in getOrgIdentityPermission DAL operation
The open-source secret management platform: Sync secrets/configs across your team/infrastructure and prevent secret leaks.
Slack | Infisical Cloud | Self-Hosting | Docs | Website
Introduction
Infisical is the open source secret management platform that teams use to centralize their secrets like API keys, database credentials, and configurations.
We're on a mission to make secret management more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
Features
- User-friendly dashboard to manage secrets across projects and environments (e.g. development, production, etc.).
- Client SDKs to fetch secrets for your apps and infrastructure on demand.
- Infisical CLI to fetch and inject secrets into any framework in local development and CI/CD.
- Infisical API to perform CRUD operation on secrets, users, projects, and any other resource in Infisical.
- Native integrations with platforms like GitHub, Vercel, AWS, and tools like Terraform, Ansible, and more.
- Infisical Kubernetes operator to managed secrets in k8s, automatically reload deployments, and more.
- Infisical Agent to inject secrets into your applications without modifying any code logic.
- Self-hosting and on-prem to get complete control over your data.
- Secret versioning and Point-in-Time Recovery to version every secret and project state.
- Audit logs to record every action taken in a project.
- Role-based Access Controls to create permission sets on any resource in Infisica and assign those to user or machine identities.
- Simple on-premise deployments to AWS, Digital Ocean, and more.
- Secret Scanning and Leak Prevention to prevent secrets from leaking to git.
And much more.
Getting started
Check out the Quickstart Guides
| Use Infisical Cloud | Deploy Infisical on premise |
|---|---|
| The fastest and most reliable way to get started with Infisical is signing up for free to Infisical Cloud. |
View all deployment options |
Run Infisical locally
To set up and run Infisical locally, make sure you have Git and Docker installed on your system. Then run the command for your system:
Linux/macOS:
git clone https://github.com/Infisical/infisical && cd "$(basename $_ .git)" && cp .env.example .env && docker-compose -f docker-compose.prod.yml up
Windows Command Prompt:
git clone https://github.com/Infisical/infisical && cd infisical && copy .env.example .env && docker-compose -f docker-compose.prod.yml up
Create an account at http://localhost:80
Scan and prevent secret leaks
On top managing secrets with Infisical, you can also scan for over 140+ secret types in your files, directories and git repositories.
To scan your full git history, run:
infisical scan --verbose
Install pre commit hook to scan each commit before you push to your repository
infisical scan install --pre-commit-hook
Lean about Infisical's code scanning feature here
Open-source vs. paid
This repo available under the MIT expat license, with the exception of the ee directory which will contain premium enterprise features requiring a Infisical license.
If you are interested in managed Infisical Cloud of self-hosted Enterprise Offering, take a look at our website or book a meeting with us:
Security
Please do not file GitHub issues or post on our public forum for security vulnerabilities, as they are public!
Infisical takes security issues very seriously. If you have any concerns about Infisical or believe you have uncovered a vulnerability, please get in touch via the e-mail address security@infisical.com. In the message, try to provide a description of the issue and ideally a way of reproducing it. The security team will get back to you as soon as possible.
Note that this security address should be used only for undisclosed vulnerabilities. Please report any security problems to us before disclosing it publicly.
Contributing
Whether it's big or small, we love contributions. Check out our guide to see how to get started.
Not sure where to get started? You can:
- Join our Slack, and ask us any questions there.
- Join our community calls every Wednesday at 11am EST to ask any questions, provide feedback, hangout and more.
Resources
- Docs for comprehensive documentation and guides
- Slack for discussion with the community and Infisical team.
- GitHub for code, issues, and pull requests
- Twitter for fast news
- YouTube for videos on secret management
- Blog for secret management insights, articles, tutorials, and updates
- Roadmap for planned features