Full API Management
APIs, operations and policies per scope, real traffic from Log Analytics, versions and revisions, definition, consumers, products, subscriptions, named values, backends and self-hosted gateways.

Celeste brings together, in one desktop app, what your platform team does every day: testing APIs on a private API Management, checking which token each operation expects, copying secrets between Key Vaults and getting into private PostgreSQL databases without building tunnels by hand.
A secret that has to move from one vault to another, an API that only answers inside the VNet and a private database you, once again, can’t reach today.
The gateway is internal, the portal can’t reach it and neither can Postman. To test one operation you end up borrowing a VM.
The audience lives in a fragment, the scope in a variable and the issuer in a named value. Nobody knows until something returns 401.
Open a vault, reveal the value, copy it, open another vault, create the secret, pray you didn’t drop a character.

Pick an operation and hit “Test”. If the gateway lives inside a VNet, Celeste notices, finds its private IP and opens the way through Azure Bastion, direct or through a jump VM.


Celeste reads every API Management policy (global, products, APIs, operations and fragments), resolves the variables and returns every validate-jwt grouped by audience.


Celeste finds the Key Vaults in all your subscriptions and lets you pin the ones you use to the menu. Inside, everything you do in the portal, with fewer clicks.


The server is only reachable from its VNet. Celeste builds the tunnel through Azure Bastion to the jump VM, connects in a few seconds and opens pgweb so you can run queries without leaving the app.


Built for the day-to-day of platform, integration and security teams on Azure.
APIs, operations and policies per scope, real traffic from Log Analytics, versions and revisions, definition, consumers, products, subscriptions, named values, backends and self-hosted gateways.

Saved tunnels with direct or jump-VM profiles, discovered from your subscriptions. No typing az network bastion tunnel.
Import your M2M apps report and see which ones have every scope API Management requires, which fall short and which don’t match at all.

Copy a secret to another Key Vault without revealing it, create new versions and select several to export them to .env at once.
VS Code-style tabs, favorites in the sidebar and a search that finds any resource.
No Azure passwords: it uses your az session. Anything sensitive it stores is encrypted on your machine.
AureliaK8s takes care of your Kubernetes clusters. Celeste, of everything around them in Azure: gateways, secrets and databases. Same account to sign in, and both are free.
Nothing. Celeste is free, like AureliaK8s. If it saves you time, you can support the project with a donation.
The az CLI, signed in. Celeste uses that session to see your subscriptions; the Bastion hop is built in.
Through Azure Bastion. For API Management gateways and VNet-integrated PostgreSQL, it opens a tunnel to a jump VM inside the network and connects from there. You just pick the profile.
Only what you ask for: creating or copying a secret, a new version or deleting one, always with confirmation. The API Management, audiences and database views are read-only.
Nowhere. Celeste talks to Azure straight from your machine and keeps its cache and settings locally. You sign in with your AureliaK8s account, using a code sent to your email.
macOS (Apple Silicon) and Windows 10 and 11, with automatic updates.
Download Celeste, sign in with your AureliaK8s account and pick your subscriptions. In a couple of minutes your gateways, vaults and databases are one click away.