Your secrets.
Your servers.
Your pocket.
Secrets2Go is a native iOS client for Infisical, the open-source secrets manager. Check a prod API key from the train. Fix a missing staging variable before the deploy fails. Works with Infisical Cloud and any self-hosted instance.
Unofficial client — not affiliated with or endorsed by Infisical Inc. Requires an account or machine identity on an existing Infisical instance.
Built like the dashboard, sized for a thumb
Every environment at once
The secrets overview matrix shows one key across dev, staging, and prod in a single table — present, missing, or empty at a glance. Tap a column to drill into that environment.
Several instances, one screen
Add Infisical Cloud and your homelab side by side. Home lists every connection with its projects, and pins keep day-to-day paths on top.
Full read–write
Create, edit, and delete secrets and folders. Change-approval workflows are respected: a gated edit shows as pending, never silently applied.
Provisioning included
Create projects and environments, mint machine identities with one-time client secrets, and grant or revoke project access — from the phone.
Careful with clipboards
Copied values use a local-only pasteboard that clears itself after 30 seconds. Revealed values are marked privacy-sensitive, so they never appear in the app switcher.
Locked by default
Face ID or passcode gates the app. Credentials live in the iOS Keychain with the strictest accessibility class your device supports, and in-memory caches are zeroed on lock.
Speaks fluent Infisical
Universal Auth, Token Auth, and email sign-in with MFA. Write paths use legacy-compatible routes, so older self-hosted servers keep working.
Nothing passes through us
Secrets2Go talks directly to the Infisical server you configure — and to nothing else. There is no middleware, no proxy, no account with us, and no way for us to see your data even if we wanted to.
| Where your data goes | Happens |
|---|---|
| Your Infisical server, over HTTPS | ✓ the only network traffic |
| Credentials in the iOS Keychain, on device | ✓ never synced, never exported |
| Analytics, crash reporting, tracking | none — zero third-party SDKs |
| Developer-operated servers | none exist |
| Secrets in logs, backups, or iCloud | never written |
Pricing
$2.99
Pay once, own it. No subscription, no tiers, no account. Every feature listed above is in the one and only version.
Questions
Does it work with my self-hosted Infisical?
Yes — point it at any base URL. The app targets the stable v1–v3 REST APIs and keeps legacy route aliases for older servers. If your instance works with the Infisical CLI, it works here.
How do I sign in?
Three ways: a machine identity with Universal Auth (client ID + secret), a pasted access token, or your email and password — including email-code and authenticator-app MFA. SSO/SAML accounts and passkey MFA should use a machine identity instead.
Is this an official Infisical app?
No. Secrets2Go is an independent client, not affiliated with or endorsed by Infisical Inc. Infisical is a trademark of Infisical Inc.
What about change approvals?
If your project requires approvals, an edit from the app creates an approval request and the app tells you it is pending — exactly like the web dashboard, never a silent bypass.
Android?
Not yet. Secrets2Go is native SwiftUI, iPhone-first. If there is demand, an Android client would be a separate effort — tell us via the support page.