KeyEnvKeyEnv

FAQ

Frequently asked questions about KeyEnv.

Frequently Asked Questions

General

What is KeyEnv?

KeyEnv is a secrets management platform that helps teams securely store, sync, and share environment variables across development workflows. It replaces insecure practices like sharing .env files via Slack or email.

How is KeyEnv different from .env files?

Aspect.env FilesKeyEnv
SecurityUnencrypted, often committed to gitEncrypted at rest, never in git
SharingCopy/paste, email, SlackSecure team access with roles
SyncManualAutomatic with CLI
AuditNoneFull audit trail
EnvironmentsManual managementBuilt-in dev/staging/prod

Is KeyEnv free?

Yes! The Free plan includes:

  • 3 projects
  • 100 secrets per environment
  • 1 team member
  • All core features

See our pricing page for plan details.

Security

How are secrets encrypted?

Secrets are encrypted using AES-256-GCM before storage. Each secret has a unique initialization vector (IV). The encryption key is securely managed and never exposed.

Can KeyEnv employees see my secrets?

No. Secrets are encrypted at rest with keys that KeyEnv employees cannot access. We follow zero-knowledge principles for secret storage.

Is KeyEnv SOC 2 compliant?

We are working towards SOC 2 Type II compliance. Contact us for our current security documentation.

What happens if KeyEnv is down?

The CLI caches secrets locally (encrypted) so your applications continue working. Once connectivity is restored, secrets sync automatically.

CLI

How do I install the CLI?

curl -fsSL https://keyenv.dev/install.sh | bash

See the installation guide for more options.

The CLI says "not authenticated"

Run keyenv login to authenticate. If you're in a CI/CD environment, set the KEYENV_TOKEN environment variable with a service token.

How do I switch environments?

# Pull secrets from staging
keyenv pull -e staging

# Run command with production secrets
keyenv run -e production -- npm start

Can I use KeyEnv offline?

Yes, once you've pulled secrets, they're cached locally. You can work offline and sync when back online.

Teams & Collaboration

How do I invite team members?

  1. Go to your project's Team page
  2. Click Invite Member
  3. Enter their email and select a role
  4. They'll receive an invitation email

What are the different roles?

RoleCan View SecretsCan Edit SecretsCan Manage Team
MemberYesYesNo
AdminYesYesYes

Can I have different access per environment?

Yes! You can set per-environment permissions (admin, write, read, or none) for each team member. Go to Project Settings > Permissions to configure environment-level access.

CI/CD & Automation

How do I use KeyEnv in GitHub Actions?

steps:
  - name: Install KeyEnv
    run: curl -fsSL https://keyenv.dev/install.sh | bash

  - name: Pull secrets
    env:
      KEYENV_TOKEN: ${{ secrets.KEYENV_TOKEN }}
    run: keyenv pull -e production

See the CI/CD guide for more examples.

Should I use a service token or my personal login?

Always use service tokens for automation:

  • Service tokens: For CI/CD, scripts, automated processes
  • Personal login: For local development only

How do I rotate a service token?

  1. Create a new service token
  2. Update your CI/CD secrets with the new token
  3. Verify the new token works
  4. Revoke the old token

Billing & Plans

How do I upgrade my plan?

Go to Settings → Billing and click Upgrade. You'll be redirected to our secure checkout.

Can I cancel anytime?

Yes. Cancel from the billing page. You'll retain access until the end of your billing period.

Do you offer annual billing?

Annual billing with discounts is coming soon. Contact us for early access.

Troubleshooting

"Project not found" error

  • Verify you're in the correct directory (check for .keyenv.toml)
  • Run keyenv init if you haven't set up the project
  • Check that you have access to the project

"Permission denied" error

  • Verify your role has the required permissions
  • For service tokens, check the token has access to the environment
  • Try logging out and back in: keyenv logout && keyenv login

Secrets not updating

# Force a fresh pull
keyenv pull --force

# List current secrets to verify
keyenv list

Need more help?

On this page