Private beta: the source and binaries are not public yet, so the install commands do not work yet.
aisync

Your Claude Code setup, the same on every machine.

Keep settings.json, CLAUDE.md, skills, agents and MCP servers as profiles in your own private GitHub repo, and set up a new machine with one pull. Tokens travel encrypted and never sit in a config file in plain text.

~/.claude.json
"slack": {
  "command": "npx""aisync",
  "args": ["exec", "--", "npx", "-y", "server-slack"],
  "env": {
    "SLACK_BOT_TOKEN": "xoxb-1234-9f8e7d6c5b4a""{{secret:slack-bot}}"
  }
}

The token is right there. Copy or back up this file and the token goes with it.The value is not in this file. When Claude Code starts the server, aisync decrypts it and hands it to that server only.

What moves and what stays is fixed

Anything tied to an account or a machine is left alone, so after a pull your login and conversation history are still that machine's own.

Moves

  • settings.json, CLAUDE.md, keybindings.json
  • skills, agents, commands, output-styles, workflows
  • User MCP servers (tokens encrypted)
  • The plugin list in settings.json

Stays

  • Your Claude login
  • Conversation history, sessions, caches
  • skills/synced, which Claude syncs from your account itself
  • Plugin binaries

No token is left anywhere in plain text

The repo holds ciphertext, the config file holds references. The real value exists only inside the MCP server process while it runs.

GitHub repo

you/aisync-config

secrets.json (AES-256-GCM)

Encrypted with your passphrase. A leaked repo can't be opened without it.

This machine's config

~/.claude.json

"{{secret:slack-bot}}"

Only references. The decryption key lives in the macOS keychain (a 0600 file on Linux), so you type the passphrase once per machine.

The running MCP server

aisync exec

SLACK_BOT_TOKEN=xoxb-…

Handed over the moment the server starts, to that process only. Claude itself and other commands never see it.

A new machine takes four commands

Before uploading, aisync shows you every hardcoded token. Before changing a file on pull, it backs the original up.

  1. aisync scanFinds plain-text tokens in your current setup. Uploads nothing.
  2. aisync loginUses your gh login and creates a private repo if you have none.
  3. aisync capture defaultTurns this machine's setup into a profile.
  4. aisync pull defaultOn the new machine. The passphrase is asked once, here.

Several accounts, one setup

Each profile has its own Claude Code config folder, so a personal and a work account can run side by side. The work profile inherits the default one and changes only what differs.

  1. aisync new work --extends defaultCreates a work profile on top of your default setup.
  2. aisync run workStarts Claude Code with ~/.claude-work. Login and usage stay separate.

More on profiles and multiple accounts

No server, no sign-up

Storage is your GitHub repo and login is gh's. If you already run HashiCorp Vault, tokens can live there with only references in your setup. There is also an admin page to see and edit every setting in the browser.