New

Compare two parameters side by side, even across AWS accounts.

See how

Desktop tool · AWS Systems Manager

Parameter Manager: the desktop GUI for AWS Parameter Store.

Browse every parameter, edit values as .env text, and review a key-by-key diff before anything is written. A fast, careful client for the configuration your apps depend on.

v0.1.1 · Linux, Windows and macOS · Works with your existing AWS profiles, SSO included

A diff before every save

Saving is the riskiest thing you do in Parameter Store, so Parameter Manager never writes blind. Every save lists added, changed and removed keys with values masked, checks that nobody saved in between, and keeps the parameter's type, KMS key and description exactly as AWS stores them.

How saving works
The save dialog for /myapp/prod/env: one key added, one changed, values masked, and a Save new version button.

Features

Built for the way you work with parameters

Screenshots

See every parameter at a glance

The list has the same columns as the AWS console: name, tier, type, data type, version, last modified, last modified user and description. Search by name or description, sort any column, and move through your paths with a folder tree built from the names.

  • Search and sort always cover every row
  • Thousands of parameters stay fast

Edit values as .env text

Values open in a CodeMirror editor with syntax highlighting, warnings for invalid lines and duplicate keys, and a byte counter against the tier limit. JSON and plain strings open as plain text. Press Ctrl+S to review and save.

  • SecureStrings stay hidden until you decrypt them
  • Search inside the value with Ctrl+F

Version history with one-click restore

Browse every version, newest first, and see exactly which keys changed compared with the current value. Restore this version puts the old value back in the editor as unsaved changes; saving it creates a new version, so history is never rewritten.

Compare across environments and accounts

Pick a connection and a parameter for each side, such as staging against production or one AWS account against another. See how many keys differ, exist on one side only, or are equal, then read the key-by-key table. Values stay masked until you reveal them.

Connections that know what's production

A connection is an AWS profile plus a region, an optional path prefix and a color. Mark a connection read-only and every write action disappears. The main process refuses writes on it too, so a UI bug can't change production.

  • Profiles come from your AWS config and credentials files
  • Test connection before you save it

Safety

Careful by design

Every save goes through the same checks, in the same order, before anything reaches AWS.

  1. 01

    Guards first

    Empty values, SecureStrings that were never decrypted, unchanged values and anything over 8,192 bytes are stopped before a dialog opens or AWS is called.

  2. 02

    Review the diff

    Added, changed and removed keys, values masked. Going over 4 KB on a Standard parameter means ticking the Advanced tier upgrade yourself.

  3. 03

    Check the version

    The parameter is read again before writing. If someone saved in between, you choose: reload the latest, or overwrite anyway.

  4. 04

    Keep the metadata

    Type, KMS key, description, allowed pattern and data type come from what AWS holds, never from a stale list. Only the value changes.

Credentials stay in your AWS files

The app stores only connection names, profiles, regions and display settings, written atomically with file mode 0600.

A hardened Electron app

Only the main process talks to AWS. The UI is sandboxed with context isolation, no Node integration and a strict Content Security Policy.

Values are never logged

Logs hold only the error code, parameter name and message. Deleting a parameter requires typing its full name.

Get started in minutes

Parameter Manager uses the AWS profiles already on your machine. No extra keys, no account to create.

1. Install it

Download the installer for Windows, the .dmg for macOS, or the AppImage or .deb package for Linux. You need AWS profiles in ~/.aws/config or ~/.aws/credentials; static keys and SSO both work.

Download

2. Create a connection

Pick a profile and a region, add an optional path prefix and color, then press Test connection. Mark production connections read-only.

Required IAM permissions

3. Or try it without AWS

Run from source in demo mode, with 19 fake parameters and nothing sent to AWS. Requires Node.js 20.19 or newer.

npm install && npm run demo

Frequently asked questions

Ready to get started?

Download Parameter Manager and connect it to the AWS profiles you already use.

Version 0.1.1 · All releases on GitHub

Download Parameter Manager today:

  • An .env editor with warnings
  • A diff before every save
  • Version history and restore
  • Compare across accounts
  • Read-only connections