Secret Portal
by @awlevin
Spin up a one-time web UI for securely entering secret keys and env vars. Supports guided instructions, single-key mode, and cloudflared tunneling.
clawhub install secret-portalπ About This Skill
name: secret-portal description: Spin up a one-time web UI for securely entering secret keys and env vars. Supports guided instructions, single-key mode, and cloudflared tunneling. metadata: { "openclaw": { "emoji": "π", "requires": { "bins": ["uv"] }, "install": [ { "id": "uv-brew", "kind": "brew", "formula": "uv", "bins": ["uv"], "label": "Install uv (brew)", }, ], }, }
Secret Portal
Spin up a temporary, one-time-use web UI for securely entering secret keys and environment variables. No secrets ever touch chat history or terminal logs.
Quick Start
# Single key with cloudflared tunnel (recommended)
uv run --with secret-portal secret-portal \
-k API_KEY_NAME \
-f ~/.secrets/target-env-file \
--tunnel cloudflaredWith guided instructions and a link to the key's console
uv run --with secret-portal secret-portal \
-k OPENAI_API_KEY \
-f ~/.env \
-i 'Get your key:- Go to platform.openai.com
- Click API Keys
- Create new key
' \
-l "https://platform.openai.com/api-keys" \
--link-text "Open OpenAI dashboard β" \
--tunnel cloudflaredMulti-key mode (no -k flag, user enters key names and values)
uv run --with secret-portal secret-portal \
-f ~/.secrets/keys.env \
--tunnel cloudflared
Options
| Flag | Description |
|------|-------------|
| -k, --key | Pre-populate a single key name (user only enters the value) |
| -f, --env-file | Path to save secrets to (default: ~/.env) |
| -i, --instructions | HTML instructions shown above the input field |
| -l, --link | URL button for where to get/create the key |
| --link-text | Label for the link button (default: "Open console β") |
| --tunnel | cloudflared (recommended), ngrok, or none |
| -p, --port | Port to bind to (default: random) |
| --timeout | Seconds before auto-shutdown (default: 300) |
Tunneling
Use --tunnel cloudflared β it's free, requires no account, has no interstitial pages, provides HTTPS, and auto-downloads the binary if missing.
ngrok free tier shows an interstitial warning page that blocks mobile and automated use.
Without a tunnel, the port must be open in your firewall/security group. The CLI will warn you if it detects the port is unreachable.
Security
600 permissions (owner-only)Source
https://github.com/Olafs-World/secret-portal
π‘ Examples
# Single key with cloudflared tunnel (recommended)
uv run --with secret-portal secret-portal \
-k API_KEY_NAME \
-f ~/.secrets/target-env-file \
--tunnel cloudflaredWith guided instructions and a link to the key's console
uv run --with secret-portal secret-portal \
-k OPENAI_API_KEY \
-f ~/.env \
-i 'Get your key:- Go to platform.openai.com
- Click API Keys
- Create new key
' \
-l "https://platform.openai.com/api-keys" \
--link-text "Open OpenAI dashboard β" \
--tunnel cloudflaredMulti-key mode (no -k flag, user enters key names and values)
uv run --with secret-portal secret-portal \
-f ~/.secrets/keys.env \
--tunnel cloudflared
βοΈ Configuration
| Flag | Description |
|------|-------------|
| -k, --key | Pre-populate a single key name (user only enters the value) |
| -f, --env-file | Path to save secrets to (default: ~/.env) |
| -i, --instructions | HTML instructions shown above the input field |
| -l, --link | URL button for where to get/create the key |
| --link-text | Label for the link button (default: "Open console β") |
| --tunnel | cloudflared (recommended), ngrok, or none |
| -p, --port | Port to bind to (default: random) |
| --timeout | Seconds before auto-shutdown (default: 300) |