Latch

Managing your vault

Projects and environments

Add a project in the manager and select its directory. The directory binds CLI requests to that project. Each project starts with development, test, staging, and production environments. Select the environment before creating, importing, revealing, or copying secrets.

Import and expected names

Import a .env file through the native picker and review the names before committing. Existing names are reported as conflicts. Import does not erase the original plaintext file.

Compare a .env.example to find expected variable names. Latch discards the right-hand sides rather than importing example values as secrets. The parser does not execute shell expressions.

Reveal and copy

Values are concealed by default. Reveal deliberately displays one selected value. Copy stays in Rust and clears the clipboard after the selected 15, 30, or 60 seconds if its contents still match the Latch copy. Clipboard managers may retain a copy despite those controls.

Locking and the tray

The vault locks after five minutes. Closing the manager locks it and keeps the background app running. The tray provides Open Latch, Lock Vault, and Quit Latch. Closing a request popup denies that request.

Locking cannot retract a value already delivered to a process. OS-session locking and suspend integration are not implemented yet.

Recovery

Unlocking requires both your separate Latch passphrase and device material in the OS credential store. There is no passphrase reset or portable backup recovery yet. Losing either factor prevents normal unlock.

Edit this page on GitHub

On this page