Automation

Robotsson

Secrets Management for Developers, Digital Employees and AI Agents

One self-hosted home for every secret and setting, so developers, digital employees and AI agents each get the credentials they need, and only those.

The challenge

Configuration lived in .env files on every machine and was copied into the hosting platform, the backend and the CI pipelines by hand-run scripts. Nobody could say for sure which value was live where, and rotating a credential meant a round of manual edits. Then AI coding agents joined the team, and the old rule “if you can use it, you can read it” stopped being acceptable.

Our solution

  • We built Varlatch, one source of truth for every project. A contract in each repository declares which settings exist, which are secret and what type they are, and every change is checked against it.
  • Using a secret and reading it are separate permissions, so every colleague gets exactly the access they need.
  • Changes push themselves to every destination across hosting, backend and CI, and a repair pass undoes edits made outside Varlatch.

Three kinds of colleagues

Developers

Sign in with a passkey and start any app with one command. No more .env files.

Digital employees

Fetch their settings at startup with their own machine credential. Production settings can only be retrieved from approved machines on the private network.

AI agents

Get placeholders instead of secrets. The real value is filled in only for requests to destinations Robotsson allows, and every use is logged.

Results

No .env files left
One edit or rotation reaches every app automatically, and is logged
The CI pipeline signs in with its own short-lived identity and stores no long-lived secret
A regular check flags any drift
Varlatch gives every colleague, human or digital, exactly the access they need. Our AI agents work with real credentials without ever seeing them, and secrets went from a constant worry to something that simply works.
Jeremy Deceuster, Founder, Robotsson

Have a workflow like this?