Skip to content

Plugins Overview

Plugins allow extending the functionality of Varlock. Most load secrets from an external source (password managers, secrets platforms, cloud secret stores), but plugins can also extend other parts of varlock, such as adding request-transform schemes to the credential proxy. See the plugins guide for more details on using plugins.

The plugins listed below are the official ones, published under the @varlock npm scope. Third-party plugins are also supported. You can load them from npm or from a local path. See the plugins guide for more information. Loading plugins from other sources (git, http, jsr) is not supported yet.

These plugins extend the credential proxy rather than loading secrets:

Pluginnpm package
1Password
Akeyless
AWS (Secrets Manager & Parameter Store)
AWS SigV4 signing (credential proxy; AWS and S3-compatible)
Azure Key Vault
Bitwarden
Dashlane
Doppler
Google Secrets Manager
HashiCorp Vault (and OpenBao)
Infisical
KeePass
Keeper
Kubernetes (Secrets & ConfigMaps)
macOS KeychainN/A - built-in
Pass (unix password manager)
Passbolt
Proton Pass