HushLane

Login Get Started Free

◆ NIST FIPS 203/204 Compliant · Harvest-Now, Decrypt-Later Proof

Your secrets survive Q-Day.

A post-quantum secure vault for developers. Store API keys and credentials in zero-knowledge encryption, sync them directly to your terminal via CLI, and share them safely.

curl -sSf https://www.hushlane.dev/install.sh | sh

Free up to 10 secrets · No credit card required

Key Features & Capabilities

🔐 Post-Quantum Zero-Knowledge Vault

Uses NIST FIPS 203 ML-KEM-768 key encapsulation paired with AES-256-GCM. Harvest-now, decrypt-later attacks by quantum computers fail.

⚡ Terminal-First Secret Sync

Pull secrets directly into your local .env or process environment with hushlane pull. No file left on disk.

📬 Secret Request Links

Send a secure link to anyone. They submit credentials in their browser (encrypted end-to-end) without needing a HushLane account.

🔁 Revocable Expiring Shares

Share secrets with contractors or teammates with custom expiration dates. Auto-revokes access when the engagement ends.

🔑 OS Keychain Integration

Private decapsulation keys stay locked in macOS Keychain, Windows Credential Manager, or Linux libsecret. Never written as plain text files.

📁 Project-Scoped Security

Isolate client and application credentials cleanly by project. Pull only what you need per application container.

End-to-End Encrypted Secret Sharing & Request Links

📬 Secret Request Links (Zero-Knowledge)

Need client credentials or API tokens safely? Generate a Secret Request Link. The recipient clicks the link and submits their credentials directly in their browser. Before transmission, their browser encrypts the secret using your vault's public inbox key. Plaintext secrets are never transmitted in Slack, email, or stored on HushLane servers.

🔁 Revocable Epiring Guest Secret Shares

Share passwords, ENV keys, or configs safely with contractors or teammates. Create temporary guest links that automatically expire after a specified duration (e.g., 2 hours, 1 day, or 7 days). You can revoke access instantly with a single click in your dashboard, ensuring maximum security and granular control over external dependencies.

How It Works

  1. Step 0: Install the CLI — curl -sSf https://www.hushlane.dev/install.sh | sh
  2. Step 1: Init your machine — hushlane init generates an ML-KEM-768 keypair in OS Keychain.
  3. Step 2: Link Machine (Zero-Knowledge) — Paste key in Web Portal. Browser encapsulates vault key so server never sees plain credentials.
  4. Step 3: Pull Secrets — hushlane pull --project my-app decapsulates locally and populates secrets.

Pricing Plans

Free Plan

$0 / forever

  • Up to 10 secrets
  • ML-KEM-768 + AES-256-GCM
  • CLI .env sync
  • 3 active secret request links

Pro Plan

$5 / month

  • Unlimited secrets
  • Unlimited secret request links
  • Revocable expiring shares
  • Unlimited machine clients

HushLane — Post-Quantum Zero-Knowledge Secrets Manager for Developers. Built with ML-KEM-768, AES-256-GCM, and Argon2id.

Privacy Policy · Terms of Service · Contact Us