Secret Manager
by @jswortz
Manage API keys securely via GNOME Keyring and inject them into OpenClaw config.
clawhub install secret-managerπ About This Skill
name: secret-manager description: Manage API keys securely via GNOME Keyring and inject them into OpenClaw config. homepage: https://github.com/openclaw/skills metadata: {"clawdbot":{"emoji":"π","requires":{"bins":["secret-tool","systemctl","python3"]},"install":[{"id":"bash","kind":"bash","bin":"secret-manager.sh","label":"Install Secret Manager (bash)"}]}}
Secret Manager
A secure way to manage API keys for OpenClaw using the system keyring (GNOME Keyring / libsecret).
This skill provides a secret-manager CLI that:
1. Stores API keys securely using secret-tool.
2. Injects them into your auth-profiles.json.
3. Propagates them to systemd user environment.
4. Restarts the OpenClaw Gateway service inside your Distrobox container.
Installation
Ensure you have the dependencies:
sudo apt install libsecret-toolssudo dnf install libsecretsudo pacman -S libsecretCopy the script to your path or run it directly.
Configuration
The script uses default paths that work for most OpenClaw installations, but you can override them with environment variables:
| Variable | Description | Default |
| :--- | :--- | :--- |
| OPENCLAW_CONTAINER | Name of the Distrobox container | clawdbot |
| OPENCLAW_HOME | Path to OpenClaw config directory | ~/.openclaw |
| SECRETS_ENV_FILE | Path to an optional .env file to source | ~/.config/openclaw/secrets.env |
Usage
List all configured keys:
secret-manager list
Set a key (interactive prompt):
secret-manager OPENAI_API_KEY
(Paste key when prompted)
Set a key (direct):
secret-manager DISCORD_BOT_TOKEN "my-token-value"
Supported Keys:
OPENAI_API_KEYGEMINI_API_KEYDISCORD_BOT_TOKENGATEWAY_AUTH_TOKENOLLAMA_API_KEYGIPHY_API_KEYGOOGLE_PLACES_API_KEYLINKEDIN_LI_ATLINKEDIN_JSESSIONIDπ‘ Examples
List all configured keys:
secret-manager list
Set a key (interactive prompt):
secret-manager OPENAI_API_KEY
(Paste key when prompted)
Set a key (direct):
secret-manager DISCORD_BOT_TOKEN "my-token-value"
Supported Keys:
OPENAI_API_KEYGEMINI_API_KEYDISCORD_BOT_TOKENGATEWAY_AUTH_TOKENOLLAMA_API_KEYGIPHY_API_KEYGOOGLE_PLACES_API_KEYLINKEDIN_LI_ATLINKEDIN_JSESSIONIDβοΈ Configuration
The script uses default paths that work for most OpenClaw installations, but you can override them with environment variables:
| Variable | Description | Default |
| :--- | :--- | :--- |
| OPENCLAW_CONTAINER | Name of the Distrobox container | clawdbot |
| OPENCLAW_HOME | Path to OpenClaw config directory | ~/.openclaw |
| SECRETS_ENV_FILE | Path to an optional .env file to source | ~/.config/openclaw/secrets.env |