Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
16 results
label:vault

Gcp Sm

@swamp/gcp-sm · v2026.09.10.0

Read, write, and delete secrets stored in Google Cloud Secret Manager, with

upd Sep 1017 pullsA100/100

Azure Kv

@swamp/azure-kv · v2026.09.10.0

Read, write, and delete secrets stored in Azure Key Vault. Supports secret

upd Sep 10291 pullsunscored

Aws Sm

@swamp/aws-sm · v2026.09.10.0

Read, write, and delete secrets stored in AWS Secrets Manager, with support

upd Sep 10697 pullsA100/100

1password

@swamp/1password · v2026.09.10.0

Read, write, delete, and annotate secrets stored in 1Password using the `op` CLI.

upd Sep 1036k pullsA100/100

Pass

@webframp/pass · v2026.08.28.1

GPG-encrypted password store using the pass CLI (passwordstore.org). Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.

upd Aug 2828 pullsA100/100

Macos Keychain

@webframp/macos-keychain · v2026.08.28.1

macOS Keychain vault using the security CLI. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and keychain service only — never secret values, argv, or error messages.

upd Aug 2856 pullsA100/100

Hashicorp Vault

@webframp/hashicorp-vault · v2026.08.28.1

HashiCorp Vault secrets management via REST API (KV v1 and v2). Emits OpenTelemetry spans for get, put, and list, with one child span per request in the recursive list walk, so vault reads are visible in traces including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and KV version only — never secret values, tokens, or error messages.

upd Aug 2880 pullsA100/100

Gopass

@webframp/gopass · v2026.08.28.1

gopass password manager (gopass.pw) - pass compatible with extra features. Emits OpenTelemetry spans for get, put, and list so vault reads are visible in traces, including reads during model and workflow runs where the host emits nothing. Span attributes carry the vault name, key name, and backend only — never secret values or error messages.

upd Aug 289 pullsA100/100

Gcp/vault

@swamp/gcp/vault · v2026.08.12.2

Google Cloud vault infrastructure models

upd Aug 120 pullsA100/100

1password Connect

@sntxrr/1password-connect · v2026.08.05.1

A swamp vault backend for 1Password Connect — read and write secrets over Connect's HTTP API with a bearer token, so vault.get() works headless in cron, containers, and swamp serve without the op CLI.

upd Aug 561 pullsA100/100

Scaleway Secret Manager Vault

@sntxrr/scaleway-secret-manager-vault · v2026.07.18.1

A swamp vault backend backed by Scaleway Secret Manager — source other models' secrets from Scaleway with vault.get(...) expressions, authenticated via X-Auth-Token.

upd Jul 180 pullsA100/100

Openbao Configurator

@evrardjp/openbao-configurator · v2026.07.17.1

OpenBao configuration rendering and API lifecycle control: render HCL, status, initialize, unseal, and seal. File deployment and service management are handled by cfgmgmt extensions.

upd Jul 172.8k pullsA100/100

Gcloud Token

@atalanta/gcloud-token · v2026.07.11.1

A read-only swamp vault that mints a fresh Google OAuth access token on every

upd Jul 113 pullsA100/100

Selfcert

@evrardjp/selfcert · v2026.07.06.1

Self-signed TLS certificate generator for Swamp: creates RSA-4096 certs locally using node:crypto and stores cert + key in a swamp vault.

upd Jul 65 pullsA100/100

Passbolt

@phy2vir/passbolt · v2026.05.25.2

Passbolt CLI vault provider for swamp secrets

upd May 258 pullsA100/100

Sops Age

@zocc/sops-age · v2026.05.22.1

SOPS + age vault for swamp: encrypt secrets at rest with AES-256-GCM via Mozilla SOPS and age. Zero network dependency — fully local, file-based. Works with existing SOPS workflows and zo.space secrets dashboards.

upd May 2223 pullsA100/100