The CLI

SealedGit, from your terminal.

shub works like gh and sgit works like git. Both come in one download built for your computer, because your computer is where SealedGit decrypts.

install
curl -fsSL https://github.com/sealedgit/sealedgit/releases/latest/download/install.sh | sh

01

Install

Yes, there is something to install. SealedGit encrypts and decrypts on your computer, never on the host, so its tools have to run there. You need two things:

  • gitThe git you already use; SealedGit works through it. On a Mac without it, run xcode-select --install.
  • SealedGitOne program for your system and processor, a few megabytes. It runs as shub, sgit, git-remote-sgit and the SealedGit app.

In one line

shell
curl -fsSL https://github.com/sealedgit/sealedgit/releases/latest/download/install.sh | sh

The installer works out your system and processor, downloads only that build, checks it against its published SHA-256, and puts it in ~/.local/bin. Nothing runs as root. On a Mac it picks the native build even in a terminal running under Rosetta. To install somewhere else, set SEALEDGIT_INSTALL_DIR for the sh at the end: … | SEALEDGIT_INSTALL_DIR=/opt/sealedgit/bin sh.

Or download it yourself

Every desktop build
ComputerArchiveChecksum
macOS, Apple siliconThis computerM-series Macs sealedgit-macos-arm64.tar.gz .sha256
macOS, IntelThis computerIntel Macs sealedgit-macos-x86_64.tar.gz .sha256
Linux, x86-64This computerglibc sealedgit-linux-x86_64.tar.gz .sha256
Linux, Arm64This computerglibc sealedgit-linux-arm64.tar.gz .sha256

From a terminal, the same thing by hand. Replace macos-arm64 with your computer’s build if it isn’t this one.

shell
curl -fLO https://github.com/sealedgit/sealedgit/releases/latest/download/sealedgit-macos-arm64.tar.gz
curl -fLO https://github.com/sealedgit/sealedgit/releases/latest/download/sealedgit-macos-arm64.tar.gz.sha256
shasum -a 256 -c sealedgit-macos-arm64.tar.gz.sha256
tar -xzf sealedgit-macos-arm64.tar.gz
mkdir -p ~/.local/bin && cp -P sealedgit-*/bin/* ~/.local/bin/

On Linux, sha256sum -c does what shasum -a 256 -c does. cp -P keeps the links as links. If you downloaded the archive in a browser and macOS says it can’t check the program, run xattr -d com.apple.quarantine ~/.local/bin/sealedgit once the checksum matches; downloads made with curl aren’t quarantined.

What’s in the download

  • sealedgitThe one program. Each name below is a link to it, and it acts as whichever name it was started by.
  • shubThe hosting CLI: accounts, repositories, members, issues, pull requests, releases.
  • sgitGit, sealed: clone, push, pull and fetch over sgit://. Everything else goes to your git.
  • git-remote-sgitThe remote helper git runs for sgit:// URLs.
  • sealedgit-appThe SealedGit app, also started by shub app.
  • sealedgit-browseA viewer for one repository, also sgit browse.

They share almost all of their code, so they ship as one program rather than five, which makes the download about a quarter of the size.

Verify a release

Each release publishes a manifest of every archive’s SHA-256 and size, signed through Sigstore by the workflow that built it. The manifest names archives by version; the download above is the same file, so its SHA-256 matches the entry for your computer.

shell
curl -fLO https://github.com/sealedgit/sealedgit/releases/latest/download/manifest.json
curl -fLO https://github.com/sealedgit/sealedgit/releases/latest/download/manifest.sigstore.json
cosign verify-blob manifest.json --bundle manifest.sigstore.json \
    --certificate-oidc-issuer https://token.actions.githubusercontent.com \
    --certificate-identity-regexp '^https://github\.com/sealedgit/sealedgit/\.github/workflows/ci\.yml@refs/tags/v'

02

Connect and sign in

  1. Connect to your service

    Give shub the accounts address. It looks the host up from there.

    shell
    shub config connect https://accounts.example.com
  2. Create your account

    Here, or on the web. Then confirm your address from the email: open its link, or run shub auth verify --token with the token in it.

    shell
    shub auth signup --email you@example.com --password '…' --handle you

    Your handle is your username: lower-case letters, digits and hyphens, 2 to 39 characters. Passwords are at least 10 characters.

  3. Sign in

    Signing in enrols this computer as a device and prints its safety number, the fingerprint others compare before they admit you.

    shell
    shub auth email-login --email you@example.com --password '…'
  4. Open the app, if you like

    The same repositories in your browser, served from this computer and decrypted here.

    shell
    shub app

03

Your first repository

Create it, clone it, and commit as you always do. sgit push seals the commit before it leaves your machine.

shell
shub repo create ledger --clone && cd ledger
echo "opening balance 0" > BALANCES.md
sgit add BALANCES.md && sgit commit -m "open the ledger"
sgit push

--description adds an encrypted description, and --object-format sha256 makes a SHA-256 repository. shub repo list shows every repository you own or belong to.

04

Everyday git

sgit handles the four commands that talk to the host. Everything else passes straight through to your git, options and all.

CommandWhat happens
sgit clone you/ledgerFetches ciphertext and decrypts it on your device. -b picks a branch.
sgit pushSeals your commits into an encrypted bundle and a signed RefHead, then uploads them.
sgit pullFetches and decrypts, then merges or rebases locally, as git pull does.
sgit fetchFetches and decrypts without touching your working tree. --prune works.
sgit anything elseYour own git: status, log, diff, branch, rebase, stash and the rest.

Works as you’d expect

  • branches
  • tags
  • force-with-lease
  • submodules
  • SHA-256 repositories

Not over sgit://: shallow and partial clones, atomic multi-ref pushes, push options and signed pushes. Each needs a host that reads the repository; here is why.

05

Working with others

An invitation is not access. Access starts when your device admits theirs.

  1. Invite them

    This emails a link and grants nothing. Add --forward-only to start them at a snapshot of today’s tree rather than the whole history.

    you
    shub repo invite-email you/ledger --email teammate@example.com
  2. They accept, and read you their digest

    They sign up from the link, or sign in and accept with the account they already have. Then, on the computer they’ll use, shub device publish-key-package prints that device’s full digest, which they read out to you over a channel you trust.

    teammate
    shub auth accept-invite --token <token from the email>
    shub device publish-key-package
  3. Admit their device

    See who is waiting, then admit them pinned to the digest they gave you. If the host served a different key, the digest won’t match and nobody is admitted.

    you
    shub repo admissions --repo you/ledger
    shub repo admissions --repo you/ledger --user <their handle> --key-package-digest <their digest>
  4. They join

    Their device opens the Welcome your admission produced, and from then on it decrypts like yours.

    teammate
    shub repo accept-welcome you/ledger
    sgit clone you/ledger

To remove someone, shub repo remove-member you/ledger <handle>. It moves the repository to a new epoch, so nothing pushed afterwards opens for them. shub repo invitations lists what you’ve sent, and shub repo revoke-invitation withdraws one that hasn’t been admitted.

06

Issues, pull requests and releases

The same work as on any host, encrypted to the repository’s members. Inside a checkout, --repo can be left out.

shell
# issues
shub issue create --repo you/ledger --title "Settlement rounds half-cents down" --body "…"
shub issue list --repo you/ledger

# pull requests and review, once the branch is pushed
shub pr create --repo you/ledger --head fix-rounding --title "Round half to even"
shub pr review 1 --repo you/ledger --verdict approve --body "transfer() is atomic now"
shub pr merge 1 --repo you/ledger

# releases: notes encrypted, assets sealed
shub release create --repo you/ledger --tag v0.4.0 --notes "…" --asset dist/ledger.tar.gz

Review verdicts are approve, request_changes and comment.

07

Large files

SealedGit doesn’t speak the Git LFS wire protocol, which hands file contents to the server as they are. shub lfs keeps large files as sealed objects instead, and commits small pointer files in their place.

shell
shub lfs track "*.psd"
shub lfs push
sgit add -A && sgit commit -m "add artwork" && sgit push

# on another member's computer
shub lfs fetch

08

Check your setup

CommandTells you
shub --versionWhich release you have.
shub auth statusWho you are signed in as.
shub config getWhich host and accounts service this computer uses.
shub crypto reportThe ciphersuite and AEAD linked into your copy: MLS_256_MLKEM1024_AES256GCM_SHA512_MLDSA87, NIST Category 5.
shub doctorLocal keychain and repository tip diagnostics.

09

Command reference

The commands you’ll use most. shub help <command> lists every option.

CommandFor
shub authSign up, confirm, sign in and out, reset a password, accept an invitation, personal access tokens.
shub configConnect this computer to a service; show its settings.
shub repoCreate, list, view and clone repositories; invite, admit and remove members; verify the RefHead chain.
shub deviceThis account’s devices and their key packages; encrypted recovery kits.
shub issue, pr, releaseEncrypted issues, pull requests, reviews and releases.
shub lfsLarge files as sealed objects.
shub appThe SealedGit app, in your browser, on this computer.
shub crypto reportWhat cryptography your copy linked.
sgit clone, push, pull, fetchGit over encrypted sgit:// remotes.
sgit anything elseYour own git, unchanged.

Ready

Install, sign in, push something sealed.

Create your account on the web or from the terminal. Either way, your keys stay on your computer.