KeyEnvKeyEnv

Workflow Commands

CLI commands for development workflow.

Workflow Commands

Commands that integrate with your development workflow.

run

Run a command with secrets injected as environment variables.

keyenv run [OPTIONS] -- <COMMAND>

Options

OptionDescription
-e, --env <ENV>Environment (default: development)

Examples

# Run npm start with secrets
keyenv run -- npm start

# Run with production secrets
keyenv run -e production -- node server.js

# Run any command
keyenv run -- python manage.py runserver

# Complex commands (use quotes)
keyenv run -- sh -c "echo $DATABASE_URL && npm test"

How It Works

  1. Fetches secrets from the server
  2. Injects them as environment variables
  3. Runs your command with those variables
  4. Secrets are never written to disk

Use keyenv run when you want secrets available but don't want a .env file on disk.


diff

Show differences between local .env file and remote secrets.

keyenv diff [OPTIONS]

Options

OptionDescription
-e, --env <ENV>Environment (default: development)

Examples

keyenv diff

# Comparing .env with development:
#   + NEW_LOCAL_KEY      (local only)
#   - REMOVED_KEY        (remote only)
#   ~ CHANGED_KEY        (modified)
#
# + local only  - remote only  ~ modified

Output

SymbolMeaning
+Key exists locally but not on server
-Key exists on server but not locally
~Key exists in both but values differ

JSON Output

keyenv diff --json
{
  "environment": "development",
  "has_differences": true,
  "differences": [
    { "key": "NEW_LOCAL_KEY", "status": "local_only" },
    { "key": "REMOVED_KEY", "status": "remote_only" },
    { "key": "CHANGED_KEY", "status": "modified" }
  ]
}

history

Show version history for a secret.

keyenv history <KEY> [OPTIONS]

Arguments

ArgumentDescription
KEYThe secret key to show history for

Options

OptionDescription
-e, --env <ENV>Environment (default: development)
-l, --limit <N>Number of entries to show (default: 10)

Examples

keyenv history DATABASE_URL

# History for DATABASE_URL (development):
#   v3  2024-01-15 10:30  [email protected]  postgres://prod...
#   v2  2024-01-10 14:22  [email protected]  postgres://staging...
#   v1  2024-01-05 09:00  [email protected] postgres://dev...

JSON Output

keyenv history DATABASE_URL --json
{
  "key": "DATABASE_URL",
  "environment": "development",
  "history": [
    {
      "version": 3,
      "changed_at": "2024-01-15T10:30:00Z",
      "changed_by": "[email protected]",
      "value_preview": "postgres://prod..."
    }
  ]
}

Values are partially masked in the output. Use keyenv get to retrieve the full value.

On this page