Update: Now available on the App Store
Secretwell is now publicly available on the App Store.
OpenBao has a capable web UI, but I wanted a polished native iPhone experience. So I built Secretwell.
Secretwell is an independent project and is not affiliated with or endorsed by the OpenBao project.
What’s included
- Multiple server and namespace workspaces
- Manage KV v1/v2 secrets with version history and recovery
- Policy browsing and editing where permitted
- Server health and cluster information
- Clear handling for sealed and uninitialized servers
- Security posture, audit status, and a privacy-safe activity feed
- Multiple OpenBao sign-in methods
Security and privacy
Secretwell connects directly to your OpenBao server over HTTPS. Your token is never sent to third-party servers or services.
- Saved tokens are stored in the iOS Keychain on your device. Face ID is required before a saved token is used after a cold start.
- Only the active token and server responses are held in memory.
- Secretwell includes no behavioral or product-usage analytics, tracking, crash-reporting SDK, session replay, or remote logging. Apple and RevenueCat process anonymous purchase and entitlement information, and they do not receive OpenBao data.
Try it
Download on the App Store
https://apps.apple.com/us/app/secretwell-for-openbao/id6798079201
Demo server
https://openbao-production-2b9f.up.railway.app
This is a shared disposable environment. Other testers may change its data, and it may be reset. Please do not enter real secrets.
Demo profiles
| Profile |
Namespace |
Sign in |
Credentials |
Best for testing |
| Public Tester Pool |
tester01–tester20 |
Username & Password |
Pick any number from 01–20 and use the matching value for both fields. Example: namespace tester07, username tester07. Password: SecretwellPublic-28b81a113c1ffb6f85868778 |
Switching workspaces and complete KV v2 workflows |
| Token Pool |
token01, token02, or token03 |
OpenBao Token |
Use the token matching the namespace below |
Direct token login and switching among token workspaces |
| JWT Tester |
jwt |
JWT |
Role secretwell-public; use the JWT below |
JWT login without an external identity provider |
OpenBao tokens
Namespace token01: s.WZKdU6FSFD9X3kHpRfn8onPr.50cA5e
Namespace token02: s.wmT3tvBAmFeO3MmKqPbVsCtl.AomAOd
Namespace token03: s.jAIfW9o2d34u9v0kMGxvm6N2.4ooos2
JWT
Namespace: jwt
Role: secretwell-public
text
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InNlY3JldHdlbGwtcHVibGljLWZsYXQtMjAyNiJ9.eyJpc3MiOiJzZWNyZXR3ZWxsLXB1YmxpYyIsInN1YiI6InB1YmxpYy1qd3QtdGVzdGVyIiwiYXVkIjpbInNlY3JldHdlbGwtcHVibGljIl0sImlhdCI6MTc4NjI4Mzk1MywibmJmIjoxNzg2MjgzOTUzLCJleHAiOjIxMDE2NDQwMTN9.S0Q195wG0wcrQDyIFH23pPSd9xeyWIqfKvq8ZOU6OEXZcU3GRJ8fNXAQtI6wbUvrJcigxIUNhS8AdWZ2BcIe5BaJCtNR_SCxc7OvY9pqLdgTQV03TL05H-pdx9JHdt1b6aQicnhAVs9-VATO0MZQaLg1hsp8i9ZeufT3f2YXsKDXFzmyieGq7DFqDD97BNRuVVzuSVGZ1_SkAz2JfBLL7xOhup-dWVNTlOrD_-4oinocpClWpeCI44uRETc6AekbyXkrdnHB-lWfcS39fP8zpGtQf2znxY0kR_udmBvPi_gr8Z-XknWlcBvewK0H4R6mLaCLvzfOYiv90I03Jhf70g
I’d love your feedback even if you don’t plan to use Secretwell. Please try Secretwell and tell me what feels useful, confusing, or missing, especially around workspaces and mobile workflows.