Local-first, open-source dashboard that:
- Scans every project in a chosen Vercel team and inventories its environment variable metadata (key name, targets, secret/plain type).
- Attributes each variable to a likely third-party service (AWS, Neon, Stripe, …) using a configurable rule set.
- Tracks rotation state — which variables you have rotated since the last scan, with timestamps and an audit log.
- Rotates values via the Vercel REST API with a guarded modal, without ever persisting environment variable values on disk.
Read the full plan in docs/PLAN.md.
- No Vercel npm packages and no Vercel CLI: only
https://api.vercel.comvia the globalfetch. - No Vercel-branded UI packages: the UI is plain HTML / CSS / vanilla JS.
- Minimal runtime dependencies — see
docs/DEPENDENCIES.md.
- Node.js >= 20 (uses global
fetchand the built-in test runner). - A Vercel API token. The app's onboarding wizard will walk you through creating one.
npm install
npm run build
npm startThe server binds to http://127.0.0.1:4319 by default. Open that URL in
your browser. On first run you will be sent through the Onboarding
Wizard:
- Choose a passphrase (used to encrypt the API token at rest).
- Open Vercel and create a token (the wizard provides the link).
- Paste the token; the app verifies it by calling Vercel.
- Pick the team / organization to scan.
- Optionally mint a narrower, dashboard-specific token.
By default, the app stores data under ./data/ (gitignored):
inventory.sqlite— metadata, scans, rotation audit. No secret values.credentials.bin+credentials.salt— encrypted Vercel token blob.
You can override the directory with VSD_DATA_DIR=/some/path npm start.
- Default vendor rules:
config/vendor-rules.default.json - Optional override: place a
vendor-rules.override.jsonnext to it (or in the data directory) to add or replace rules. - Suggestions for unmatched keys are written to
data/vendor-rules.suggested.jsonafter each scan.
See SECURITY.md for the threat model and how to report
issues. In short: the SQLite file contains variable names and metadata
and should be treated as sensitive. The API token is encrypted at rest.
Environment variable values are never persisted.
Domain-Driven Design with hexagonal layering:
src/
domain/ # entities, value objects, domain errors (no IO)
application/ # use cases + port interfaces
infrastructure/ # Vercel REST client, SQLite repos, crypto
interface/ # local HTTP server + static UI assets
See docs/PLAN.md §6 for the full breakdown.
npm testUses the built-in node --test runner; no separate test framework.
MIT — see LICENSE.
