Cloud sync

Preview. Cloud sync is optional and still in preview. Everything else in keygrant works without it, and nothing is uploaded until you run keygrant push.

How it protects your values

Set up the first device

uv tool install 'keygrant[cloud]'     # adds the crypto dependency (PyNaCl)
keygrant cloud init                   # choose a password; prints your Emergency Kit

cloud init prints your Emergency Kit: the Account ID and the Secret Key. Write it down and keep it offline, on paper and not in a synced notes app. With the kit and your password you can recover even if every device is gone. Print it again later with keygrant cloud kit.

Upload secrets

Nothing leaves the machine until you push it:

keygrant push STRIPE_KEY OPENAI_KEY        # upload these

Day to day

echo "sk-..." | keygrant set STRIPE_KEY && keygrant push STRIPE_KEY   # add or change
keygrant push --delete STRIPE_KEY                                     # remove everywhere
keygrant sync                                                          # pull now
keygrant cloud status                                                  # account, devices, sync state

keygrant list and keygrant exec pull changes on their own, at most once a minute, and silently skip it when you’re offline, so you rarely need sync.

Conflicts

More devices

Add a second machine by pairing it from one you already have, or with the Emergency Kit alone if no old device is at hand.

Leaving

keygrant cloud delete

This permanently deletes the account, all ciphertext and every paired device. Secrets stay on each machine as local-only entries and keep working. You’ll be asked to type the Account ID to confirm.