Tool Open source

jit

jit is a local-first macOS command-line secrets manager from jitpass that moves development credentials from plaintext files such as .env, AWS credentials, shell exports, npm configuration, and MCP configurations into an encrypted vault protected by Touch ID. It rewrites source files with decoys so existing tools can continue working while the real value is released only to an authorized process.

View repository Visit site Mentioned in 1 video ↓

Overview

It provides credentials through per-process environment injection, native credential protocols such as AWS credential_process and Docker or Git credential helpers, and a named-pipe mount for tools that only read files. The named pipe is a mode-0600 POSIX FIFO: authorized reads receive decrypted values through the kernel pipe buffer without writing them to disk, while ambient readers receive decoys. jit is macOS-only for Apple Silicon and is still in development; the project states that it does not protect credentials after they enter the requesting process's memory.

What jit is used for

1 use taken from transcripts — each links to the moment in the video.

  • Moves development secrets from plain-text dot files into a local encrypted vault protected by Touch ID. Existing tools can access credentials through helpers, environment injection, or a named pipe, with request logging and bounded grants for agents.

Videos mentioning jit

1 in the library.