Portable Data
Anvil keeps everything local and encrypted. Exports leave secrets out unless you choose an encrypted mode, and imports never run anything.
SHA256SUMS. macOS installers are not Developer ID signed or notarized and Windows installers have no code-signing certificate. In-app updates use verified minisign signatures; this does not code-sign the installers. See the preview downloads and Anvil overview.Where Data Lives
| Platform | Default data directory |
|---|---|
| macOS | ~/Library/Application Support/Ferrum Anvil/ |
| Windows | %APPDATA%\Ferrum Anvil\ |
| Linux | $XDG_DATA_HOME/Ferrum Anvil/ (default ~/.local/share/Ferrum Anvil/) |
ANVIL_DATA_DIR (or --data-dir on the CLI) overrides the location. Each profile has its own encrypted database. Workspaces, requests and revisions, environments, secrets, profiles, datasets, load plans and reports, history and settings are sealed with XChaCha20-Poly1305; only structural fields such as ids, kinds and timestamps stay in the clear.
Three Export Modes
Secrets are excluded by default. Include them only in encrypted form.
| Mode | Contents | Secrets |
|---|---|---|
| Share safely (default) | One workspace | None. Literal secrets become {{placeholders}} listed in the bundle manifest, so the recipient knows what to fill in. |
| Encrypted transfer | One workspace | Vault secrets, encrypted with an export passphrase you share separately. |
| Full backup | Everything, including history and settings | Encrypted. Restores into a new profile on a clean machine without the original keychain or data key. |
Exports and backups never include a linked sign-in identity, and restoring someone else's backup cannot replace yours.
Preview, Then Apply
- Every import shows a preview first. Conflicts are resolved by duplicate, merge or replace.
- Bundles are checked for size limits, path traversal, symlinks, archive bombs and checksums. A wrong passphrase is rejected before anything changes.
- A checkpoint is taken and the import runs as one transaction; a failure rolls back to the checkpoint.
- Imports never send requests, run scripts or start load plans. Imported scenarios and load plans are marked untrusted and never start on their own.
- Risky settings are switched back to safe values, and the preview lists each change: TLS verification bypasses, plain-HTTP marker trust, cross-origin credential forwarding, the legacy HMAC opt-in, the 0-RTT early-data opt-in, and sending a JWT-SVID that failed its local checks. Profiles that would use this machine's SPIFFE Workload API identity are listed for review.
- Device-bound items such as keychain entries, provider sessions and linked local files are reported as needing rebinding.
- A database or bundle written by a newer schema is refused rather than modified.
Specs import separately: OpenAPI 2.0–3.2, WSDL 1.1, Postman, Insomnia, cURL and HAR, each with a preview report. External references and DTDs are not fetched.
What Leaves Anvil Is Redacted
- Secrets are redacted by name and by the exact values used in a run, across execution records, history, reports, exports and support bundles.
- The effective-request preview shows headers such as
Authorizationredacted, and the secret never reaches the page. - Load-test failure samples are built only from redacted records, and response bodies are not kept in them.
- History can be turned off, can drop response bodies, and can be limited by age and total size.
When Something Goes Wrong
| Situation | What to do |
|---|---|
| Forgot the passphrase | Use the recovery key on the lock screen, then set a new passphrase. Without the recovery key the data cannot be decrypted. |
| Lost machine or reinstall | Restore a full backup, with its export passphrase, into a new profile. |
| Bad import | Nothing to do: the failed import was rolled back to its checkpoint. |