Redshift CLI for Decentralized Secret Management for Openclaw

Redshift is a decentralized secret management tool that uses Nostr relays for client-side encrypted storage, eliminating the need for central servers.

accolver
v0.2.0
Feb 18, 2026
0
1.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install redshift

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install redshift using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Redshift CLI for Decentralized Secret Management?

Redshift is a high-performance command-line interface designed for developers who prioritize cryptographic security and decentralization. By integrating Openclaw Skills, users can manage application secrets, API keys, and sensitive environment variables across diverse infrastructures. Unlike traditional secret managers that rely on centralized cloud vaults, Redshift utilizes the Nostr protocol and NIP-59 Gift Wrap for client-side encryption. This ensures that sensitive data is encrypted before it ever leaves your machine and is stored across a distributed network of relays, providing a resilient and private alternative to standard solutions.

Through the implementation of Openclaw Skills, Redshift allows for seamless authentication via Nostr private keys (nsec) or remote bunkers (NIP-46). It is built to support complex development lifecycles, offering per-directory project configurations and environment-specific secret isolation. Whether you are deploying to a self-hosted homelab or a massive cloud cluster, Redshift provides a secure, local-first experience with the flexibility of a decentralized backend.

Redshift CLI for Decentralized Secret Management Use Cases

  • Securely managing environment variables for backend applications without a central vault.
  • Injecting encrypted secrets into CI/CD pipelines using Nostr authentication and Openclaw Skills.
  • Synchronizing project-specific secrets across distributed team members via decentralized Nostr relays.
  • Local development secret management with easy handoff between development, staging, and production environments.
  • Replacing plaintext .env files with client-side encrypted storage to prevent accidental exposures.

How Redshift CLI for Decentralized Secret Management Works

  1. The user authenticates with a Nostr private key (nsec) or a remote bunker using the Redshift CLI.
  2. A project is initialized using Openclaw Skills with a redshift.yaml file, defining the project slug and the list of Nostr relays.
  3. Secrets are encrypted locally on the user's machine using NIP-59 Gift Wrap encryption, ensuring no plaintext data is transmitted.
  4. The encrypted payloads are published to the specified Nostr relays as decentralized events.
  5. When commands like redshift run are executed, the CLI fetches and decrypts the secrets into memory to inject them as environment variables or mounted files.

Redshift CLI for Decentralized Secret Management Setup

To start using this skill with Openclaw Skills, ensure you have the Redshift binary installed. You can install it from the official repository or build it from source.

# Install and login
redshift login

# Initialize a project environment
redshift setup -p my-project -c development

# Set your first secret
redshift secrets set API_KEY 'your-secret-value'

For CI/CD environments, configure the REDSHIFT_NSEC environment variable to bypass interactive login prompts.

Redshift CLI for Decentralized Secret Management Data Schema & Taxonomy

Redshift organizes data using a hierarchical structure based on projects and environments. Configuration is managed via the local file system and global settings stored in the user directory.

Component Description
redshift.yaml Project-level configuration file stored in the working directory.
~/.redshift Global configuration directory for user settings and secure keychains.
Project Slug A unique identifier (e.g., 'backend') used to group related secrets.
Environment Slug A label (e.g., 'production') for stage-specific variable isolation.
Nostr Relays The decentralized infrastructure where encrypted events are stored.

Redshift CLI for Decentralized Secret Management Advanced Features

  • Use redshift run --mount to inject secrets as temporary files instead of environment variables for improved security.
  • Multi-identity support via NIP-46 NostrConnect for remote signing and secure bunker integration within Openclaw Skills.
  • Batch operations for secret management including bulk JSON uploads and format-specific downloads (env, yaml, docker).
  • Built-in web UI via redshift serve for a visual management interface accessible on localhost.
  • Offline fallback support using local JSON snapshots for high-availability production environments.

SKILL.md


Loading

Related Openclaw Skills

Featured*