OpenBao secrets engine for short-lived, scoped GitHub App installation tokens. Fork of martinbaillie/vault-plugin-secrets-github ported to the OpenBao SDK.
-
Updated
Oct 4, 2026 - Go
OpenBao secrets engine for short-lived, scoped GitHub App installation tokens. Fork of martinbaillie/vault-plugin-secrets-github ported to the OpenBao SDK.
Git credentials broker — mints short-lived, repo-scoped tokens on demand for sandboxed clients
Configure an OpenID Connect (OIDC) identity provider and associated AWS IAM roles to enable authentication and authorisation in AWS using OIDC ID tokens
JIT Ephemeral Access Broker in Go — zero-trust just-in-time privileged access with PagerDuty/Jira validation, HashiCorp Vault token brokering, and automatic 60-min self-destructing credentials. DevSecOps, PAM, ephemeral access.
A Model Context Protocol (MCP) server that provides a security layer for managing short-lived credentials and tokens. Eliminates hardcoded API keys by issuing time-limited, scoped credentials with comprehensive audit logging and policy enforcement for GitHub, AWS, GCP, Azure, and OAuth2.
Mint a scope-exact Cloudflare API token, hand it to a command, burn it on the way out.
Stop storing CLOUDFLARE_API_TOKEN in CI. Trade your job's OIDC token for a short-lived, least-privilege Cloudflare API token or R2 credentials, minted per job and revoked when it ends: GitHub Actions, GitLab CI, or any OIDC issuer.
To associate your repository with the short-lived-credentials topic, visit your repo's landing page and select "manage topics."