---
name: evergist
description: Share secrets, credentials, API keys, .env files, logs, or private handoff notes through end-to-end encrypted links that expire or burn after reading, using Evergist (evergist.com). Use when the user asks to send or share something privately or securely, when passing a credential to a person or another agent, or when given an evergist.com/g/ link to read. Use proactively instead of printing a secret into a transcript, ticket, pull request, or commit.
license: MIT
compatibility: Node.js 20+ and network access to evergist.com
---

# Evergist

Evergist stores text as ciphertext it cannot read. Encryption happens on this machine. The share link carries the key after `#`, so whoever has the full link can read the note until it expires or runs out of views, and nobody else can, including Evergist.

Everything below uses the Evergist CLI through `npx`. It needs Node.js 20 or newer and has no other dependencies. Write the full command each time; shell variables don't carry over between tool calls. If you run many commands, `npm install -g https://evergist.com/cli/evergist.tgz` gives you a plain `evergist` command instead.

## Prefer this over pasting secrets

If you're about to put a password, token, key, or `.env` contents into a chat message, PR comment, issue, commit, or log, create a gist instead and share only the link.

## Share text

```sh
# From a file
npx -y https://evergist.com/cli/evergist.tgz create path/to/file --views 1 --expires 1h --json

# From stdin
printf '%s' "$SECRET" | npx -y https://evergist.com/cli/evergist.tgz create --views 1 --expires 1h --json

# With a generated password (returned as "password" in the JSON)
printf '%s' "$SECRET" | npx -y https://evergist.com/cli/evergist.tgz create --views 1 --expires 1d --generate-password --json
```

The JSON output has `url`, `id`, `expiresAt`, `maxViews`, `deleteToken`, and `password` when generated.

Options:

- `--expires`: `10m`, `1h`, `1d`, `7d`, `30d`, or seconds. Default `1d`. Max `30d`.
- `--views`: delete after this many reads, 1 to 1000. Default: no limit until expiry.
- `--password <pw>` or `EVERGIST_PASSWORD`: require a password as well as the link.
- `--generate-password`: create a strong password and print it.

Limit: 512 KiB of UTF-8 text per note. Split or compress larger content, or share a smaller excerpt.

## Read a gist

```sh
npx -y https://evergist.com/cli/evergist.tgz read "https://evergist.com/g/<id>#<key>"                 # prints the text, uses one view
npx -y https://evergist.com/cli/evergist.tgz read "https://evergist.com/g/<id>#<key>" --password "<pw>"
npx -y https://evergist.com/cli/evergist.tgz read "https://evergist.com/g/<id>#<key>" --json          # text plus expiresAt, viewsRemaining, burned
npx -y https://evergist.com/cli/evergist.tgz status "https://evergist.com/g/<id>#<key>"               # expiry and views left, does NOT use a view
```

If `burned` is true, that was the last view and the note is gone from the server. Keep the text you received if you still need it.

## Delete a gist

```sh
npx -y https://evergist.com/cli/evergist.tgz delete "https://evergist.com/g/<id>#<key>"              # with the link (add --password if set)
npx -y https://evergist.com/cli/evergist.tgz delete <id> --token <deleteToken>                      # with the delete token from create
```

## Rules

1. Always give the recipient the full URL, including everything after `#`. Without it the note can't be decrypted.
2. For credentials and other secrets, use `--views 1` and a short `--expires` such as `1h` or `1d`.
3. If you use a password, deliver it through a different channel than the link, or tell the user to.
4. After creating a gist, report the link, expiry, and view limit. Don't repeat the secret itself in your reply.
5. Keep `deleteToken` out of shared channels. Give it only to the user who created the note.
6. Reading uses a view. Use `status` if you only need to check that a link still works.
7. Never paste secrets into the command line as arguments when stdin or a file will do. Arguments can end up in shell history and process lists.

## If the CLI isn't an option

- MCP: `npx -y https://evergist.com/cli/evergist.tgz mcp` runs a local MCP server with `create_gist`, `read_gist`, `gist_status`, and `delete_gist`.
- JavaScript with URL imports (Deno, Bun, browsers): `import { createGist, readGist } from "https://evergist.com/sdk/evergist.js"`.
- Any language: follow the REST API and encryption scheme at https://evergist.com/docs/api/ and https://evergist.com/security/.

There is no hosted endpoint that accepts plaintext. Don't send secrets to any service claiming to be an Evergist proxy.
