Add the secondary-persona path from docs/BROWSER-ROTATION.md: ingest a password manager / browser store, take a mandatory verified sealed backup, generate fresh strong passwords, hand the human a ready-to-finish task at the MFA wall, and commit the new value into the manager only after the site change is confirmed. - internal/pwgen: crypto/rand generator (rejection sampling, per-class guarantee, vault-native — never returns plaintext as a Go string). - internal/pwstore: Manager/ItemUpdater/BulkImporter contracts, secrets-free RedactIdentity, and five adapters — bitwarden (bw, stdin), keepassxc (keepassxc-cli, stdin), 1password (op, argv assignment with documented caveat), chrome/firefox (tmpfs CSV ingest-and-shred). All real code; validation status is data (MOCK-ONLY against fake binaries/CSVs, recorded in the design doc). - internal/pwstore/stage.go: age-sealed staged-list (WriteStaged/ReadStaged) + StagedImporter — the only artifacts crossing the plan->commit gap, never plaintext. - cmd/incredigo: passwords scan|plan|guide|commit. Backup gate seals + round-trip verifies before any commit; guide is interactive verify-before-commit; commit is headless over a sealed stage. Browser CSV writes are gated behind --allow-csv. Hard rules honored: backup-before-commit, verify-before-commit, no plaintext on disk (browser CSV is the flag-gated tmpfs+shred exception), MFA always a human handoff. go vet + -race clean; end-to-end verified against a fake bw. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Incredigo
Guards your credentials in locked memory. Leaves no trace on disk.
Local-first, encrypted, RAM-only credential custody — shipped as the incredigo CLI.
+------------------------------------------------------------+
| /\ INCREDIGO |
| /<>\ in-CRED-i-GO : credentials, in Go |
| \<>/ Guards your credentials in locked memory. |
| \/ Leaves no trace on disk. |
+------------------------------------------------------------+
Incredigo finds credentials scattered across the usual places
(~/.aws/credentials, .env files, ~/.netrc, SSH keys,
~/.docker/config.json, kubeconfig, …), migrates them into a
gopass (GPG-backed) store without ever writing
plaintext to disk, and tells you which ones are stale.
- 🔒 No plaintext at rest. Disk only ever holds GPG blobs (gopass) or openssl-sealed backups.
- 🧠 RAM-only secrets. Decrypted material lives in
mlock'd, non-dumpable, zeroized memory (memguard). - 📴 Offline. v1 makes zero network calls.
- 👀 Read-only discovery. Scanners never touch your source files.
- 🧩 Hackable. A new source is one file; the backup format is an interface.
See DESIGN.md for the architecture and threat model.
Why the name
Incredigo is one word hiding three:
in · CRED · i · GO
└┬─┘ └┬┘
CREDentials in GO
It manages your CREDentials, it's written in GO, and read aloud the whole thing lands on incredible — which is the bar a credential tool that promises "no plaintext on disk, ever" has to clear.
The mark
The logo is Strata — nested diamonds tightening around a single bright core. It's the whole tool in one glyph: each ring is a layer of custody (read-only discovery → locked-memory vault → GPG/OpenSSL at rest), and the core is your secret, held in RAM and never written out. The design is deliberately abstract and geometric — no mascot, no metaphor to decode.
| What it does | How |
|---|---|
| Finds, doesn't guess | Real parsers per source — no blind grep, no false positives. |
| Composes, doesn't invent | Battle-tested GPG (via gopass) and OpenSSL; no home-rolled crypto to break. |
| Holds, doesn't leak | Read-only discovery, RAM-only custody, redacted audit log — plaintext never leaves the locked arena. |
| Works, then vanishes | No server, daemon, network, or temp files; it does its job and leaves nothing on disk. |
The brand is Incredigo, and so is the command: the CLI was renamed from its old
working title credrot so the tool and the project finally share a name.
Status
v1 scope: discover + migrate + expiry tracking. Provider-driven rotation (issue-new / verify / revoke-old) is planned for v2 behind a stable interface.
export/import are stubbed in this scaffold (see cmd/incredigo/main.go).
Rename in progress: the Go package and binary are being renamed
credrot→incredigo. Until that lands, substitute./cmd/credrot/credrotin the commands below.
Build
Requires Go 1.22+.
go mod tidy
go build ./cmd/incredigo
Usage
incredigo scan --dry-run # see what's out there (no secrets printed)
incredigo migrate --prefix imported/ --dedupe
incredigo status # age vs policy
incredigo export --out ~/incredigo-backup.enc # (v1 stub)
Layout
| Path | Purpose |
|---|---|
cmd/incredigo |
cobra CLI |
internal/vault |
RAM-only secret arena (memguard) |
internal/discover |
scanner registry + one file per source |
internal/sink |
gopass writer + Sealer interface + openssl impl |
internal/policy |
expiry rules |
internal/audit |
redacted append-only log |
Contributing
Adding a source is intentionally easy — see
docs/ADDING_A_SCANNER.md.