Full Reference All CLI commands on a single page.
Quick reference for all KeyEnv CLI commands.
Command Description keyenv loginAuthenticate with KeyEnv keyenv logoutClear stored credentials keyenv whoamiDisplay current user
Command Description keyenv initInitialize project in current directory keyenv projectsList all projects keyenv switch <project>Switch to a different project
Command Description keyenv pullPull secrets to .env file keyenv pushPush .env secrets to server keyenv listList secret keys keyenv get <key>Get a secret value keyenv set <key> <value>Set a secret keyenv delete <key>Delete a secret keyenv exportExport secrets to various formats
Export secrets to various formats (dotenv, JSON).
Command Description keyenv exportExport secrets to stdout keyenv export -e <env>Export from specific environment keyenv export -f <format>Export in format (dotenv, json) keyenv export -o <file>Export to file
Option Description -e, --env <ENV>Environment to export from (default: development) -f, --format <FORMAT>Output format: dotenv, json (default: dotenv) -o, --output <FILE>Write output to file instead of stdout
# Export as dotenv to stdout
keyenv export
# Export production secrets as JSON
keyenv export -e production -f json
# Export to a file
keyenv export -o .env.local
Command Description keyenv run -- <cmd>Run command with secrets keyenv diffCompare local and remote keyenv history <key>View secret history
Command Description keyenv permissions listList permissions for an environment keyenv permissions set <email> <role>Set a user's permission (none/read/write/admin) keyenv permissions delete <email>Remove a user's permission keyenv permissions myShow your permissions for all environments
Manage service tokens for CI/CD and programmatic access.
Command Description keyenv tokens listList all service tokens keyenv tokens create --name <name> --scope <scope>Create a new service token keyenv tokens revoke <id>Revoke a service token keyenv tokens rotate <id>Rotate a service token
Option Commands Description -n, --name <NAME>create Token name -s, --scope <SCOPE>create Token scope: read, write, admin (repeatable) -p, --project <ID>create Project ID (defaults to current project) -e, --env <ID>create Restrict to a specific environment ID --expires <DAYS>create Token expiry in days (omit for never) -y, --yesrevoke Skip confirmation prompt --grace-period <MINS>rotate Grace period in minutes for old token (default: 5, max: 60)
# List all tokens
keyenv tokens list
# Create a read-only token for CI
keyenv tokens create --name deploy-ci --scope read
# Create an admin token that expires in 90 days
keyenv tokens create --name admin-token --scope admin --expires 90
# Revoke a token
keyenv tokens revoke st_abc123
# Revoke without confirmation
keyenv tokens revoke st_abc123 --yes
# Rotate a token with 30-minute grace period
keyenv tokens rotate st_abc123 --grace-period 30
Manage teams and team members.
Command Description keyenv team listList your teams keyenv team create <name>Create a new team keyenv team show <id>Show team details and members keyenv team use <id>Set default team for current session keyenv team invite <email> [role] [--team <team_id>]Invite a member (default: member) keyenv team role <team> <user> <role>Update a member's role keyenv team remove <team> <user>Remove a member from a team keyenv team invitations <team>List pending invitations keyenv team revoke-invite <team> <invitation>Revoke a pending invitation keyenv team resend-invite <team> <invitation>Resend an invitation email keyenv team delete <team>Delete a team keyenv team audit <team>View team audit log
Option Commands Description roleinvite Role for invited user: admin or member (default: member) -y, --yesremove, revoke-invite, delete Skip confirmation prompt
# List all teams
keyenv team list
# Create a new team
keyenv team create "My Team"
# Show team details
keyenv team show team_abc123
# Set default team for the session
keyenv team use team_abc123
# Invite a member
keyenv team invite [email protected] member --team team_abc123
# Invite as admin
keyenv team invite [email protected] admin --team team_abc123
# Change a member's role
keyenv team role team_abc123 user_xyz admin
# Remove a member
keyenv team remove team_abc123 user_xyz
# List pending invitations
keyenv team invitations team_abc123
# Revoke a pending invitation
keyenv team revoke-invite team_abc123 inv_xyz
# Resend an invitation email
keyenv team resend-invite team_abc123 inv_xyz
# Delete a team (requires confirmation)
keyenv team delete team_abc123
# View audit log
keyenv team audit team_abc123
Command Description keyenv scanScan directory for hardcoded secrets keyenv scan <path>Scan specific path keyenv scan --severity <level>Filter by severity (critical, high, medium, low) keyenv scan --jsonOutput findings as JSON keyenv scan --uploadUpload scan results to KeyEnv for tracking keyenv scan --hookInstall pre-commit hook keyenv scan --hook --removeRemove pre-commit hook
Check for and install CLI updates.
Command Description keyenv update checkCheck if a new version is available keyenv update installDownload and install the latest version
# Check for updates
keyenv update check
# Current version: 0.5.0
# Latest version: 0.6.0
# Run 'keyenv update install' to update
# Install the latest version
keyenv update install
Manage automatic secret rotation configurations.
Command Description keyenv rotations listList all rotation configurations keyenv rotations show <id>Show details of a rotation keyenv rotations trigger <id>Manually trigger a rotation keyenv rotations history <id>View rotation execution history
Option Description -e, --env <ENV>Environment (default: development)
# List all rotations
keyenv rotations list
# Show rotation details
keyenv rotations show rot_abc123
# Manually trigger a rotation
keyenv rotations trigger rot_abc123
# View rotation history
keyenv rotations history rot_abc123
Command Description keyenv completions <shell>Generate shell completion script
Supported shells: bash, zsh, fish, powershell, elvish
Bash (add to ~/.bashrc):
source <( keyenv completions bash)
Zsh (add to ~/.zshrc):
# Option 1: Direct source
source <( keyenv completions zsh)
# Option 2: Save to fpath (faster startup)
keyenv completions zsh > ~/.zfunc/_keyenv
# Then ensure ~/.zfunc is in fpath and run: autoload -Uz compinit && compinit
Fish (run once):
keyenv completions fish > ~/.config/fish/completions/keyenv.fish
PowerShell (add to profile):
keyenv completions powershell | Out-String | Invoke-Expression
Option Description --jsonJSON output -q, --quietMinimal output --no-colorDisable colored output -v, --verboseEnable verbose output -h, --helpShow help -V, --versionShow version
Flag Commands Description -e, --envMost Target environment -f, --forcepull, push Overwrite without asking
Variable Description KEYENV_TOKENService token for authentication KEYENV_API_URLCustom API server URL
Code Meaning 0Success 1General error 2Authentication error 3Not found