Integrations
Optional sync targets for encrypted control files and operational workflows. They sit outside the cryptographic primitive; local encrypt, decrypt, and decoy creation keep working without them.
CLI
Command-line tool for local crypto with no network calls. No API key needed for local operations.
Install
npm install -g deny-sh
Commands
Encrypt a message37 lines
# Encrypt a message
deny-sh encrypt -m "my secret" -p1 "pass1" -p2 "pass2" -o encrypted.dat
# Decrypt
deny-sh decrypt -i encrypted.dat -c control.dat -p1 "pass1" -p2 "pass2"
# Create a deniable decoy
deny-sh deny -i encrypted.dat -p1 "pass1" -p2 "pass2" -m "fake message" -o decoy-control.dat
# Protect a seed phrase (interactive)
deny-sh protect
# Encrypt .env files
deny-sh env protect .env
deny-sh env restore .env.deny
# Local vault (SQLite, never leaves your machine)
deny-sh vault set my-key "my-value"
deny-sh vault get my-key
deny-sh vault list
deny-sh vault delete my-key
# Generate random control data
deny-sh generate -s 1024 -o control.dat
# Run verification suite
deny-sh verify
# Check installation status
deny-sh status
# Initialize .deny/ directory in your project
deny-sh init
# Pipe from stdin
echo "my secret" | deny-sh encrypt -p1 "pass1" -p2 "pass2"
cat secrets.json | deny-sh encrypt -p1 "pass1" -p2 "pass2" -o secrets.enc.deny/ directory convention
Run deny-sh init in any project to create a .deny/ directory. It auto-generates a .gitignore entry to keep local secret material out of new commits. Review already-tracked files separately. Control files, encrypted backups, and vault data all live here.
Full CLI docs: deny.sh/cli
Password setup in the protect wizard
The deny-sh protect wizard deliberately pairs each control file with its own password: real password plus real control file opens the real message; decoy password plus decoy control file opens the fake. This is a convenience wrapper around the same encryption primitive. The browser, core SDK and core CLI instead use both passwords together, with the control file selecting the output.
Keep the matching password and control file together in your recovery instructions, and store real control files separately from ciphertext. The Telegram bot currently sends encryption commands to browser tools; do not send secrets or passwords in chat.
1Password integration
Push and pull encrypted control files to 1Password. Requires the op CLI to be installed and authenticated.
# Push control data to 1Password
deny-sh 1p push -l "Wallet backup" -c control.dat
# Pull control data from 1Password
deny-sh 1p pull -l "Wallet backup" -o control.dat
# List stored items
deny-sh 1p list
# Check connection status
deny-sh 1p status
Control data is stored as a Secure Note in your 1Password vault. The note contains base64-encoded control data and metadata (label, timestamp, ciphertext hash).
Bitwarden integration
Push and pull encrypted control files to Bitwarden. Requires the bw CLI to be installed and authenticated.
# Push control data to Bitwarden
deny-sh bw push -l "Wallet backup" -c control.dat
# Pull control data from Bitwarden
deny-sh bw pull -l "Wallet backup" -o control.dat
# List stored items
deny-sh bw list
# Check connection status
deny-sh bw status
Handles BW_SESSION management automatically. Stored as Secure Note type 2 items.
Cloud backup
Encrypted archive backups to Google Drive, Dropbox, S3, or local disk. Archives use a DENY_BACKUP_V1 envelope containing an encrypted inner bundle: version 0x03 is current (Argon2id t=3, m=64 MiB, p=1, 32-byte salt, 16-byte IV, AES-256-CTR); version 0x02 is legacy-compatible with the same KDF/cipher and a 16-byte salt.
Backup to local disk23 lines
# Configure provider and defaults
deny-sh backup config
# Backup to local disk
deny-sh backup push --provider local --dest ~/backups/
# Backup to Google Drive
deny-sh backup push --provider gdrive
# Backup to Dropbox
deny-sh backup push --provider dropbox
# Backup to S3
deny-sh backup push --provider s3
# Restore from backup
deny-sh backup pull --provider local --src ~/backups/deny-backup-2026-04-05.enc
# List backups
deny-sh backup list --provider local
# Toggle automatic backup after encrypt
deny-sh backup auto --enableBackups include your vault, control files, and .deny/ directory. The archive is encrypted with your passwords before upload, so cloud providers receive encrypted content, plus whatever metadata their services collect.
Chrome extension: developer installation
Encrypt and decrypt in a browser extension, with a right-click action for text. For a no-install trial, use the browser encryptor.
Features
- Popup with Encrypt, Decrypt, and Vault tabs
- Right-click context menu for in-page encryption
- Shadow DOM panel (no CSS conflicts with host page)
- File drag-and-drop for binary encryption
- Auto-save and find control files
- Clipboard auto-clear after 30 seconds
- Manifest V3, Web Crypto API (all crypto runs locally)
Install
Installation scope. Load the extension/ directory as an unpacked extension. Distribution is through the source package, not a Chrome Web Store listing.
Full extension docs: deny.sh/extension
Telegram bot: links & saved control files
@denyshbot currently directs encrypt, decrypt and seed-protection commands to browser tools instead of collecting secrets in chat. Do not send passwords or seed phrases to the bot. It can still list and retrieve control files already saved in its own bot vault.
Commands
/start - Get started
/encrypt - Open the browser encryption tool
/decrypt - Open the browser tool to decrypt
/protect - Open the browser seed-phrase tool
/vault - List saved control files
/help - Show help
/cancel - CancelWhat stays in Telegram
The bot offers downloads of saved control files as .dat documents and a deletion flow with confirmation. These are bot-vault items, not the standard hosted vault API described above. Keep real control files separate from ciphertext and follow the password instructions on the tool you actually use.
The older in-chat encryption handlers remain in the source, but the current command entry points do not start those flows. Deleting a chat message is not a guarantee that Telegram no longer retains it.
Bot overview: deny.sh/telegram
Secrets-manager connections
For the hosted connection settings, open the integrations dashboard. See how deny.sh works alongside a secrets manager.
Recovery & inheritance
For local recovery instructions, read the protect wizard password setup. Keep the matching passwords and control files in your recovery instructions, separately from the encrypted data.