Overview & Philosophy

Ephemeral Secret Vault & Environment Injector

Muth encrypts environment secrets into muth.lock using native X25519 and SSH id_ed25519 keys, decrypting payloads in RAM during child process execution.

Key Capabilities

  • Zero Plaintext Secrets on Disk: Decrypts secrets directly into cmd.Env memory buffers.
  • Native Age Format: Full interoperability with standard age recipient stanzas.
  • Dedicated Auto-Identity: Auto-generates ~/.muth/identity silently on first run.