Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

CLI guide

Use unv describe --json to obtain the machine-readable command contract for the installed version. The common workflow is:

unv status
unv entry add GitHub --type password --username alice --key-stdin
unv get GitHub --field api_key --reveal --out token.txt
unv doctor

Use stdin for secret input where possible. Avoid --reveal on interactive shells, transcripts, or CI logs. unv backup archive creates a recoverable backup containing the vault database and its salt.

The CLI can connect to a remote vault only after a certificate pin is recorded; this prevents a self-signed or local server from becoming an unauthenticated trust exception.

Bundles

A bundle is one card for several entries that belong together (a service's password, its web session and its API app). Members stay ordinary entries.

unv bundle new "Discord bot" --member bot=DiscordBot --member web=DiscordWeb
unv bundle new "Discord bot" --import config.py     # a Python config module, read as data
unv bundle add "Discord bot" Spotify --slot api
unv bundle remove "Discord bot" api                 # detach; the entry is kept
unv bundle dissolve "Discord bot"                   # members return to the grid
unv bundle delete "Discord bot" --yes               # deletes the members too
unv get bundle:Spotify/api --field ID               # the bundle: selector

References use the same selector: ${bundle:Spotify}, ${bundle:Spotify/api}, ${bundle:Spotify/api/ID} and ${bundle:Spotify/prefix} for a bundle-local variable. An ambiguous bundle name resolves to nothing rather than to a guess.

--import never executes the file. It reads string and f-string literals, numbers, booleans and None; anything else is kept as source text with a warning that names the line. A name assigned twice keeps the first value and imports the second as name_2, and later f-strings are rewritten to match.

Files a tool reads

unv emit Npm                       # lists the formats this entry's type offers
unv emit Npm --as npmrc --out ~/.npmrc
unv emit Prod-DB --as dsn --out db.env
unv emit Home-WiFi --as wifi-uri --reveal

emit writes the credential, so it follows export: refused to stdout without --reveal, and written 0600 with --out. Formats: npmrc, pypirc, cargo-credentials, docker-config, netrc (registry tokens); dsn, libpq, jdbc (databases); wifi-uri (Wi-Fi).

Web sessions

unv cookie import capture.txt                       # preview, writes nothing
unv cookie import capture.txt --entry Site --create
unv cookie import export.har --origin https://www.example.com --entry Site
unv cookie import cookies.sqlite --from firefox --host example.com --entry Site

Accepts DevTools Copy as cURL (bash, cmd or PowerShell), HAR, Set-Cookie lines and a Firefox profile's cookies.sqlite. Only the chosen origin's cookies and headers are kept; an Authorization header and other hosts' cookies are dropped and listed by name, never by value. Chrome is refused by name: its cookies are not readable from outside the browser.

OAuth and recovery codes

unv oauth refresh Slack            # ONLINE: sends the refresh token to its token_url
unv codes status GitHub-codes
unv codes next GitHub-codes --reveal   # reading does not spend a code
unv codes use GitHub-codes             # mark the next one used

oauth refresh stores a rotated refresh token in the vault before it reports anything, because the issuer has already invalidated the old one.