init / login / logout / status
agentsecrets init
agentsecrets init agentsecrets init --server https://api.agentsecrets.yourcompany.com
Creates your account, generates encryption keys locally, and sets up your first workspace. On returning machines, detects existing accounts and walks you through joining your workspace. Accepts --server <URL> (points to a self-hosted server), --storage-mode 1 (keychain only) or --storage-mode 2 (keychain and .env). Defaults to keychain only.
During interactive setup, you are prompted to select between the default AgentSecrets Server and a self-hosted server instance.
Additionally, it automatically generates a local .agent/workflows/agentsecrets.md file (the OpenClaw skill) which teaches any AI assistants operating in the directory how to safely use the AgentSecrets CLI without exposing your credentials.
agentsecrets login
agentsecrets login agentsecrets login --server https://api.agentsecrets.yourcompany.com
Authenticates an existing account on a new machine. Does not generate new keys — pulls your existing workspace key from the server after authentication. Use --server <URL> to authenticate against a self-hosted server.
agentsecrets logout
agentsecrets logout
Clears the local session. Does not delete your keychain entries or cloud secrets.
agentsecrets status
agentsecrets status
Shows current user, workspace, project, environment, server target (default vs self-hosted), proxy status, and last sync time. Run this before any secrets operation to confirm you are in the right context.