The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →git-secret lets a team keep selected files encrypted in a Git repository, so authorized collaborators can decrypt them locally when needed. In the long-standing sobolevn/git-secret project, the workflow uses Git and GPG: add files to the managed list, encrypt them before committing, and reveal them only on a machine with an authorized user’s private key.
This guide covers that GPG-based command set. A separate project lineage documents different commands and key handling, so do not combine instructions across them without confirming which repository and release you have installed.
What git-secret does—and what it does not do
git-secret is a Bash command-line tool for storing encrypted data in a Git repository. In the GPG workflow, it encrypts selected files for authorized users’ public keys; an authorized user later uses their private key to decrypt those files. See the project documentation and usage documentation.
It is not a general-purpose secret vault or a way to make plaintext safe after it has been exposed. Its protection depends on encrypting files before they enter Git history, keeping private keys private, and managing authorized public keys correctly. If plaintext is committed, encrypting a later copy does not erase the earlier version from repository history.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitches#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What you need before setup
- Git and GPG installed. The installation documentation lists supported installation approaches and identifies both as dependencies.
- A Git repository where you can control which files are tracked and committed.
- A GPG key pair for each person who needs to decrypt the files. Each person should keep their private key secure and share only their public key.
- A trusted way to verify public keys before adding them. The project recommends using a secure or trusted encrypted channel for key exchange; an unverified key could belong to someone else.
Set up the GPG workflow
- Initialize the repository for git-secret. From the repository, run
git secret init. This creates the.gitsecretstructure. - Add an authorized user. Run
git secret tell <email>, using the email associated with that user’s GPG key. Confirm that the key is the intended person’s key before granting access. - Register files to protect. Run
git secret add path/to/filefor each plaintext file you want git-secret to manage. Registering a file does not itself mean you should commit its plaintext. - Encrypt before committing. Run
git secret hide. Commit the encrypted output, not the plaintext files. A pre-commit hook or an equivalent team process can help catch modified files that have not been encrypted. - Decrypt locally when needed. An authorized user runs
git secret revealto restore plaintext in their working copy. Keep the revealed files out of Git commits.
For the exact command behavior and key-management details, follow the usage documentation for the release you installed: git-secret usage. The project’s installation page covers installation methods.
Share access and handle membership changes
Granting access
First verify and import the new collaborator’s public key, then add that user to the repository’s git-secret keyring using the documented command for your installed release. A newly added user does not automatically gain access to ciphertext already created for the previous keyring. An existing authorized member must re-encrypt the files with the updated keyring and commit the updated encrypted artifacts.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Removing access
Remove the person’s key from the active keyring and re-encrypt the files so future ciphertext is not addressed to that key. This is not retroactive erasure: someone who was previously authorized may still have copied plaintext, ciphertext, or other key material. Removing access cannot retrieve those copies.
Prevent common leaks
- Do not commit unmanaged plaintext. Confirm protected files are registered and encrypted before committing. A plaintext file that Git tracks can expose its contents in commits or history.
- Automate the final check. Use a pre-commit hook or another reliable team procedure to encrypt changed plaintext before a commit is created.
- Protect private keys. Do not commit GPG private keys or share them with teammates. Each authorized user should retain control of their own private key.
- Verify public-key identity. Get public keys through a trusted channel and verify their fingerprints rather than treating an email address alone as proof of identity.
- Follow the installed version’s repository rules. Treat
.gitsecretmetadata and any implementation-specific key files as sensitive configuration. Use the ignore rules and guidance for the exact project lineage and release in use.
git-secret or GitHub Actions secrets?
These address overlapping needs but use different storage and access models. git-secret versions encrypted files in Git and leaves key management and local decryption with the team. GitHub repository, organization, and environment secrets are submitted encrypted with Libsodium sealed boxes and made available to explicitly configured workflows. GitHub’s documentation describes the available scopes and controls at Using secrets in GitHub Actions.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Consideration | git-secret (GPG workflow) | GitHub repository/Actions secrets |
|---|---|---|
| Where secrets live | Encrypted files and metadata are committed to Git; authorized users decrypt locally with private key material. Project documentation; usage. | Secrets are submitted encrypted with Libsodium sealed boxes and exposed to configured workflows. GitHub documentation. |
| Who manages keys and access | The team manages GPG keys, verifies key authenticity, updates the keyring, and re-encrypts files when membership changes. Usage documentation. | GitHub handles service-side decryption and provides repository, organization, and environment scopes. GitHub documentation. |
| Collaboration and controls | Encrypted artifacts move through ordinary Git commits, reviews, pulls, and pushes. The team must maintain its own key-distribution and encryption discipline. Project documentation; usage. | Access can be configured through organization policy and environment approval controls, alongside workflow configuration. GitHub documentation. |
| Main operational risk | Key authenticity, local tooling, re-encryption after access changes, and accidentally committing plaintext. Usage documentation. | Dependence on the platform, correct workflow configuration, and avoiding secret exposure in logs. GitHub documentation. |
Choose based on where secrets must be consumed and who should control them. git-secret fits files that need to travel with a repository while remaining encrypted at rest in Git, provided the team can operate GPG and reliably manage access. GitHub Actions secrets fit values supplied to GitHub-hosted workflows and teams that prefer platform-managed storage and scopes. Neither approach makes careless handling safe: workflows can expose secrets, and local decryption can create plaintext that must be kept out of commits.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check which git-secret project you installed
There are two documentation lineages with materially different commands. This article describes the long-standing sobolevn/git-secret GPG workflow and its init, tell, add, hide, and reveal commands. The hashberg-io/git-secret documentation describes another implementation with commands such as init! and keygen!, a 24-word mnemonic, AES-256 ciphertext, and SHA3-256 integrity hashes. Those are not interchangeable setup instructions; check the repository and version before following a command guide.
Quick Recap
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

