Paladin Import (bulk credential onboarding)
Move credentials out of plaintext and into the encrypted Paladin vault, in bulk, from three kinds of sources — without the secret values ever passing through your (the agent's) context. You see names, kinds, and counts; the values flow directly from the source into AES-256-GCM inside the tool's process.
Quick Reference
| Action | Invocation |
|---|---|
| Find where credentials live (report-only) | source=discover |
| Import a .env file | source=env, path=/path/to/.env |
| Import every .env under a directory | source=env, path=/dir, recursive=true |
| Import a password-manager CSV export | source=csv, path=/path/to/export.csv |
| Import a JSON secrets dump | source=json, path=/path/to/secrets.json |
| Import from Bitwarden | source=bitwarden, search="api key" |
| Import from 1Password | source=1password, from_vault="Main" |
| Preview without writing | any of the above + dry_run=true |
CSV covers Chrome, Firefox, Bitwarden, LastPass, 1Password, and KeePass exports
offline (no CLI needed) — the value column is auto-detected from the header.
JSON accepts a flat {"NAME": "value"} object or an array of {name, value}.
Arguments
source(required):discover|env|csv|json|bitwarden|1passwordpath: forenv— a .env file or a directory to scan; forcsv/json— the filerecursive: forenv—trueto scan subdirectoriespattern: forenv— filename pattern (default.env*)search: forbitwarden/1password— only matching itemsfolder: forbitwarden— only items in this folderfrom_vault: for1password— only items in this 1Password vaultprofile: paladin profile to import into (defaultdefault)dry_run:trueto preview; nothing is writtenoverwrite:trueto replace already-vaulted names (default: skip them)
The intended agent workflow
source=discover— see what exists (env files, shell-rc export NAMES, whetherbw/opare installed and unlocked). Nothing is imported.- Relay the discovery to the human; let them choose sources.
- Import each chosen source (use
dry_run=truefirst if unsure). - Report the counts and any
git-tracked/git-unignoredflags — those credentials were exposed to git and should be rotated, not just vaulted.
Requirements
- The vault must be unlockable non-interactively:
PALADIN_PASSPHRASEorPALADIN_KEYFILEmust be set (or runpaladin initfirst). If not, the tool returnslocked: truewith instructions instead of prompting. - Bitwarden:
bwCLI installed and unlocked (export BW_SESSION=$(bw unlock --raw)). - 1Password:
opCLI installed and signed in (op signin).
What this tool will never do
- Print, return, or log a secret value — reports carry names/kinds/sources.
- Import on
discover— discovery is report-only; importing takes an explicit source invocation. - Re-import silently over existing entries — duplicates are skipped unless
overwrite=trueis explicitly passed.