# FAQ

Frequently asked questions about KeyEnv.

Source: https://keyenv.dev/docs/getting-started/faq/

## General

### What is KeyEnv?

KeyEnv is a secrets management platform that helps teams securely store, sync, and share environment variables across development workflows. It replaces insecure practices like sharing `.env` files via Slack or email.

### How is KeyEnv different from .env files?

| Aspect | .env Files | KeyEnv |
|--------|-----------|--------|
| Security | Unencrypted, often committed to git | Encrypted at rest, never in git |
| Sharing | Copy/paste, email, Slack | Secure team access with roles |
| Sync | Manual | Automatic with CLI |
| Audit | None | Full audit trail |
| Environments | Manual management | Built-in dev/staging/prod |

### Is KeyEnv free?

Yes! The Free plan includes:
- 3 projects
- 100 secrets per environment
- 1 team member
- All core features

See our [pricing page](/pricing) for plan details.

## Security

### How are secrets encrypted?

Secrets are encrypted using AES-256-GCM before storage. Each secret has a unique initialization vector (IV). The encryption key is securely managed and never exposed.

### Can KeyEnv employees see my secrets?

No. Secrets are encrypted at rest with keys that KeyEnv employees cannot access. We follow zero-knowledge principles for secret storage.

### Is KeyEnv SOC 2 compliant?

We are working towards SOC 2 Type II compliance. Contact us for our current security documentation.

### What happens if KeyEnv is down?

The CLI caches secrets locally (encrypted) so your applications continue working. Once connectivity is restored, secrets sync automatically.

## CLI

### How do I install the CLI?

```bash
curl -fsSL https://keyenv.dev/install.sh | bash
```

See the [installation guide](/docs/getting-started/installation) for more options.

### The CLI says "not authenticated"

Run `keyenv login` to authenticate. If you're in a CI/CD environment, set the `KEYENV_TOKEN` environment variable with a service token.

### How do I switch environments?

```bash
# Pull secrets from staging
keyenv pull -e staging

# Run command with production secrets
keyenv run -e production -- npm start
```

### Can I use KeyEnv offline?

Yes, once you've pulled secrets, they're cached locally. You can work offline and sync when back online.

## Teams & Collaboration

### How do I invite team members?

1. Go to your project's **Team** page
2. Click **Invite Member**
3. Enter their email and select a role
4. They'll receive an invitation email

### What are the different roles?

| Role | Can View Secrets | Can Edit Secrets | Can Manage Team |
|------|-----------------|------------------|-----------------|
| Member | Yes | Yes | No |
| Admin | Yes | Yes | Yes |

### Can I have different access per environment?

Yes! You can set per-environment permissions (admin, write, read, or none) for each team member. Go to **Project Settings > Permissions** to configure environment-level access.

## CI/CD & Automation

### How do I use KeyEnv in GitHub Actions?

```yaml
steps:
  - name: Install KeyEnv
    run: curl -fsSL https://keyenv.dev/install.sh | bash

  - name: Pull secrets
    env:
      KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
    run: keyenv pull -e production
```

See the [CI/CD guide](/docs/guides/ci-cd) for more examples.

### Should I use a service token or my personal login?

Always use service tokens for automation:
- **Service tokens**: For CI/CD, scripts, automated processes
- **Personal login**: For local development only

### How do I rotate a service token?

1. Create a new service token
2. Update your CI/CD secrets with the new token
3. Verify the new token works
4. Revoke the old token

## Billing & Plans

### How do I upgrade my plan?

Go to **Settings** → **Billing** and click **Upgrade**. You'll be redirected to our secure checkout.

### Can I cancel anytime?

Yes. Cancel from the billing page. You'll retain access until the end of your billing period.

### Do you offer annual billing?

Annual billing with discounts is coming soon. Contact us for early access.

## Troubleshooting

### "Project not found" error

- Verify you're in the correct directory (check for `.keyenv.toml`)
- Run `keyenv init` if you haven't set up the project
- Check that you have access to the project

### "Permission denied" error

- Verify your role has the required permissions
- For service tokens, check the token has access to the environment
- Try logging out and back in: `keyenv logout && keyenv login`

### Secrets not updating

```bash
# Force a fresh pull
keyenv pull --force

# List current secrets to verify
keyenv list
```

### Need more help?

- Email: support@keyenv.dev
- Documentation: [keyenv.dev/docs](/docs)
