Sync Environment Variables Across Your Team in 5 Minutes
Sync Environment Variables Across Your Team in 5 Minutes
You know the drill. A new developer joins, and they spend their first day pinging teammates on Slack: "Hey, can someone send me the DATABASE_URL?" Meanwhile, secrets scatter across DMs, pinned messages, and outdated Notion pages. Someone eventually pastes a six-month-old .env file that's missing half the keys.
There's a better way. This tutorial shows you how to share env variables with your team securely and have every developer pulling the same secrets in under five minutes.
The Problem
Most teams start with .env files. They work fine for solo projects. Then the team grows, and suddenly you're managing secrets like it's 2005:
The Slack handoff: "Can you DM me the Stripe keys?" Now your API credentials live in a searchable chat history. If anyone's account gets compromised, so do your secrets.
The stale file problem: Someone shares a .env file. A week later, the AWS credentials rotate. Now half the team has working secrets and half doesn't. Nobody knows which version is current.
The onboarding tax: New developers spend hours hunting down environment variables instead of shipping code. Worse, they might commit placeholder values to git out of frustration.
The rotation nightmare: When you need to rotate a compromised key, you have to manually notify everyone, hope they see the message, and trust they update their local files. Spoiler: someone always misses it.
These aren't hypothetical problems. A 2023 GitGuardian report found over 10 million secrets exposed in public repositories. Many of those started as "temporary" .env file shares.
Prerequisites
- A terminal (macOS, Linux, or WSL)
- Node.js, Python, or any project that uses environment variables
- 5 minutes
Step 1: Install KeyEnv
KeyEnv is a single binary with no dependencies. Install it with one command:
# macOS / Linux
curl -fsSL https://keyenv.dev/install.sh | sh
# Or with Homebrew
brew install keyenv/tap/keyenv
Verify the installation:
keyenv --version
Now authenticate with your account (free tier includes 3 projects):
keyenv login
This opens your browser for authentication. Once complete, you're ready to create your first project.
Step 2: Initialize Your Project and Add Secrets
Navigate to your project directory and initialize KeyEnv:
cd ~/projects/my-app
keyenv init
You'll be prompted to create a new project or link to an existing one:
? Project name: my-app
? Default environment: development
Created project 'my-app' with environment 'development'
Project linked. Run 'keyenv push' to upload secrets.
This creates a .keyenv file in your project root (safe to commit—it only contains the project ID, no secrets).
Now add your secrets:
keyenv set DATABASE_URL "postgres://user:pass@localhost:5432/myapp"
keyenv set STRIPE_SECRET_KEY "sk_test_abc123..."
keyenv set AWS_ACCESS_KEY_ID "AKIA..."
Or import from an existing .env file:
keyenv import .env
Check what you've got:
keyenv list
Output:
DATABASE_URL postgres://user:pass@localhost:5432/myapp
STRIPE_SECRET_KEY sk_test_abc1...
AWS_ACCESS_KEY_ID AKIA...
Your secrets are now encrypted and stored. They never leave your machine unencrypted—KeyEnv uses AES-256-GCM encryption before anything hits the network.
Step 3: Invite Your Team
Here's where team secrets sync actually happens. Invite teammates by email:
keyenv team invite team_abc123 [email protected] member
keyenv team invite team_abc123 [email protected] admin
Roles determine what teammates can do:
- Member: View and edit secrets based on environment-level permissions
- Admin: Full access to all environments, manage team members, billing, and settings
Your teammates receive an email invitation. Once they accept, they can pull secrets with two commands:
keyenv login
keyenv pull
That's it. Alice now has every environment variable she needs, properly encrypted on her machine. No Slack messages. No hunting through wikis. No stale credentials.
Step 4: Run Your App with Injected Secrets
You can export secrets to your shell:
keyenv pull
source <(keyenv export)
npm start
But there's a cleaner approach—keyenv run injects secrets directly into your process without touching your shell environment:
keyenv run -- npm start
This works with any command:
keyenv run -- python manage.py runserver
keyenv run -- docker-compose up
keyenv run -- ./my-script.sh
The secrets exist only in that process's environment. They don't persist in your shell history or leak to other processes.
Managing Multiple Environments
Real projects have multiple environments. Create them as you need:
keyenv env create staging
keyenv env create production
Switch between environments:
keyenv env use staging
keyenv pull
Or specify inline:
keyenv run --env production -- npm run deploy
Each environment has isolated secrets. Your staging Stripe keys won't accidentally end up in production.
When Secrets Change
Here's the real payoff for environment variable management at the team level. When you rotate a key:
keyenv set STRIPE_SECRET_KEY "sk_test_new_key_456..."
Every teammate gets the update on their next keyenv pull. No Slack announcements. No "did everyone update their .env?" No incident because someone missed the memo.
For sensitive rotations, you can see who has pulled the latest version:
keyenv audit --secret STRIPE_SECRET_KEY
What's Next
You've covered the basics: install, init, invite, pull. Here's what else KeyEnv handles:
- CI/CD integration: Generate service tokens for GitHub Actions, GitLab CI, or any pipeline.
keyenv token create --name "github-actions" --env production - Secret history: Roll back to previous values if something breaks.
keyenv history STRIPE_SECRET_KEY - Web dashboard: Sometimes a GUI is faster. Manage secrets at app.keyenv.dev
Check the full documentation for advanced workflows.
TL;DR: Install KeyEnv, run keyenv init, add secrets with keyenv set or keyenv import .env, invite teammates with keyenv team invite, and everyone pulls with keyenv pull. Team secrets sync in under 5 minutes, no Slack required.