[bldr]docs
CLI toolsbldr

bldr secret

Manage secrets stored in the node's secret provider

bldr secret

Manage secrets stored in the node's secret provider

bldr [BLDR FLAGS] secret <COMMAND>

bldr secret export

Export a secret payload to a JSON file (or stdout)

bldr [BLDR FLAGS] secret export <ID> [FILE]

<ID>

Secret identifier

Required.

<FILE>

Output path. When omitted the payload JSON is printed to stdout

bldr secret get

Retrieve a secret and print its payload as JSON

bldr [BLDR FLAGS] secret get <ID>

<ID>

Secret identifier

Required.

bldr secret import

Import a secret from a JSON file produced by export

bldr [BLDR FLAGS] secret import <ID> <FILE>

<ID>

Secret identifier

Required.

<FILE>

Path to a JSON file containing a SecretPayload object

Required.

bldr secret list

List all secrets (id + kind)

bldr [BLDR FLAGS] secret list

bldr secret put

Store a secret (create or overwrite)

bldr [BLDR FLAGS] secret put [PUT FLAGS] <ID>

<ID>

Secret identifier

Required.

--kind <KIND>

Kind of secret: symmetric, public, private, or metadata

Required.

--algorithm <ALGORITHM>

Algorithm (required for symmetric/public/private kinds), e.g. aes-256-gcm, ed25519, rsa-2048

--key <KEY>

Key material as a base64 or PEM string (for symmetric/public/private)

--key-file <FILE>

Path to a file whose contents become the key string (PEM or raw bytes)

--set <KEY=VALUE>

Metadata key=value pairs (may be repeated; for metadata kind)

May be given more than once.

bldr secret remove

Delete a secret

bldr [BLDR FLAGS] secret remove <ID>

<ID>

Secret identifier

Required.

On this page