The hush guide
Each page is one topic. Start with the README if you have not installed hush yet.
The same pages are a site at tryhush.dev.
- Start here — Setting up, with or without your agent · Keys in your agents’ configs · Secrets in saved conversations
- Using it — Sets · Coming from another tool · Several keys for one service · Running things · Credentials that are a file · The app · The shell hook
- Checking config — What a value should look like · Finding what a codebase needs
- Agents — Connecting your agent · What your agent gets · Adding a key off-transcript · Approvals · Policy
- Your team — Adding someone · Only some sets · Removing someone · Membership changes · Merging · CI · After someone leaves
- Other machines — Agents on other machines: hush on a tailnet · The approval relay
- Hardening — The security ladder · Touch ID · Hardware keys
- Reference — Commands · How the crypto works · What hush does not do · Architecture · Hardware unlock
- Trust — SECURITY.md (threat model, reporting) · Review scope · Red team · Every defect found · RESEARCH.md