Cachix.SecretSpec 0.21.1

dotnet add package Cachix.SecretSpec --version 0.21.1
                    
NuGet\Install-Package Cachix.SecretSpec -Version 0.21.1
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Cachix.SecretSpec" Version="0.21.1" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Cachix.SecretSpec" Version="0.21.1" />
                    
Directory.Packages.props
<PackageReference Include="Cachix.SecretSpec" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Cachix.SecretSpec --version 0.21.1
                    
#r "nuget: Cachix.SecretSpec, 0.21.1"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Cachix.SecretSpec@0.21.1
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Cachix.SecretSpec&version=0.21.1
                    
Install as a Cake Addin
#tool nuget:?package=Cachix.SecretSpec&version=0.21.1
                    
Install as a Cake Tool

SecretSpec for .NET

Supported starting with SecretSpec 0.16. A 0.15.0 package was published only to reserve the NuGet package ID; it is an unsupported bootstrap artifact and is not the C# SDK release.

Cachix.SecretSpec is the C# SDK for SecretSpec, the declarative secrets manager. It is a thin client over the shared Rust resolver, so every provider, fallback chain, profile, generator, and as_path secret behaves exactly like the CLI and the other language SDKs.

The embedded ABI is named libsecretspec in SecretSpec 0.20+. It was named secretspec-ffi through 0.19; the 0.20+ native loader accepts both shared library filename families.

dotnet add package Cachix.SecretSpec
using Cachix.SecretSpec;

using var resolved = SecretSpec.Builder()
    .WithProvider("keyring://")
    .WithProfile("production")
    .WithReason("boot web app")
    .Load();

Console.WriteLine(resolved.Secrets["DATABASE_URL"].Get());
resolved.SetAsEnv();

A missing required secret throws MissingRequiredException, whose Missing property contains the names. Other failures throw SecretSpecException, with a stable Kind.

Scopes (0.17+)

Use WithScope("api") to resolve only a named [scopes.api] subset. Both Resolved.Scope and ResolutionReport.Scope return the selected scope:

using var resolved = SecretSpec.Builder().WithScope("api").Load();

Value-free reports

Report() returns the same inventory/preflight view as secretspec check --json. It never exposes values, and a missing required secret is an entry with Status == "missing_required" rather than an exception.

var report = SecretSpec.Builder()
    .WithProfile("production")
    .WithReason("deployment preflight")
    .Report();

foreach (var secret in report.Secrets)
    Console.WriteLine($"{secret.Name}: {secret.Status}");

Typed access

Generate a C# type from the manifest, then deserialize FieldsJson():

secretspec schema |
  quicktype -s schema --top-level AppSecrets --lang csharp -o AppSecrets.cs
var secrets = AppSecrets.FromJson(resolved.FieldsJson());

Files and cleanup

An as_path secret is materialized as a mode-0400 temporary file, and Get() returns its path. Resolved implements IDisposable; keep the result in a using declaration or call Close() to remove those files when finished.

Native resolver

The NuGet package carries the resolver for glibc and musl Linux x64/Arm64, macOS x64/Arm64, and Windows x64/Arm64. Windows builds include the C runtime, so users do not need to install the Visual C++ Redistributable. The managed client is trimming-safe and supports NativeAOT; the matching native resolver remains beside the published application as a runtime asset.

dotnet publish -c Release -r linux-x64 --self-contained \
  -p:PublishAot=true

During local SDK development, SECRETSPEC_FFI_LIB can point to an explicit libsecretspec build; the SDK also discovers a Cargo target directory when used from a SecretSpec source checkout.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net8.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
0.21.1 88 9/27/2026
0.21.0 86 9/23/2026
0.20.0 641 8/31/2026
0.19.1 119 8/12/2026
0.19.0 108 8/11/2026
0.18.0 436 8/4/2026
0.17.1 125 8/1/2026
0.17.0 113 7/27/2026
0.16.0 115 7/18/2026