Secrets stay ciphertext until your code runs.

Encrypted secrets for teams. Shared only with the people, CI jobs, and processes you allow, and logged every time they are read.

Install the CLI
curl -fsSL https://keyenv.dev/install.sh | bash

Move your team over in three commands.

The .env you already have becomes encrypted, shared with the right people, and logged. Then you delete it.

acme-api — -zsh — 80×24
# link this folder to KeyEnv
➜ acme-api git:(main) keyenv init
✓ Initialized with project: acme-api
# encrypt and share your .env
➜ acme-api git:(main) keyenv push
✓ Push complete
Created: 14
# run with secrets injected
➜ acme-api git:(main) keyenv run -- npm start

> [email protected] start
> node server.js

api listening on :3000
# nothing left to leak
➜ acme-api git:(main) rm .env

Built for teams that ship from a terminal.

Every command works the same in your shell, in CI, and for your AI agent.

See all features
Nothing on disk
keyenv run hands secrets straight to your process. There is no .env file left to leak.
Access per environment
Admin, write, read, or none. The new hire gets development, not production.
Every read logged
Who read which secret, when, and from where. People, CI jobs, and AI agents alike.
Rotation and scanning
Database passwords rotate on a schedule. keyenv scan catches hardcoded keys before they ship.

Free to start. $4 a seat when the team joins.

Every plan encrypts the same way. Pay only for the people who need access.

Compare plans

Free

$0forever

  • Up to 3 projects
  • 100 secrets per environment
  • CLI access

Team

$4per user / month

  • Unlimited projects and secrets
  • Roles per environment
  • Audit logs

Stop pasting .env into Slack.

Run keyenv init in your project, and your team is on encrypted secrets in about a minute.