# AI Coding Assistants

Use KeyEnv with Claude Code, Codex, Cursor, Gemini CLI, and other AI coding tools.

Source: https://keyenv.dev/docs/guides/ai-tools/

KeyEnv publishes [Agent Skills](https://agentskills.io/) so AI coding assistants can discover and use the `keyenv` CLI automatically. When your AI tool knows about KeyEnv, it can pull secrets, set environment variables, scan for leaks, and manage rotations on your behalf.

## Supported Tools

Agent Skills work with 35+ AI coding assistants:

| Tool | Support |
|------|---------|
| Claude Code | Agent Skills |
| OpenAI Codex | Agent Skills |
| Cursor | Agent Skills |
| Gemini CLI | Agent Skills |
| GitHub Copilot | Agent Skills |
| Windsurf | Agent Skills |

## Install Agent Skills

### Automatic Installation

```bash
npx skills add keyenv/keyenv-skills
```

This installs all three KeyEnv skills:

| Skill | What It Teaches |
|-------|-----------------|
| `keyenv` | Core secrets management: auth, pull/push, set/get, list, diff, export, run |
| `keyenv-scan` | Scanning codebases for hardcoded secrets |
| `keyenv-rotate` | Database credential rotation management |

### Manual Installation (Claude Code)

Copy the skill directories to your Claude Code skills folder:

```bash
# Clone the skills repo
git clone https://github.com/keyenv/keyenv-skills.git /tmp/keyenv-skills

# Copy skills
cp -r /tmp/keyenv-skills/keyenv ~/.claude/skills/keyenv
cp -r /tmp/keyenv-skills/keyenv-scan ~/.claude/skills/keyenv-scan
cp -r /tmp/keyenv-skills/keyenv-rotate ~/.claude/skills/keyenv-rotate

# Clean up
rm -rf /tmp/keyenv-skills
```

### Manual Installation (Cursor)

Create a rule file at `.cursor/rules/keyenv.mdc`:

```yaml
---
description: Use the keyenv CLI to manage secrets and environment variables. Activate when the user mentions secrets, env vars, .env files, or keyenv.
alwaysApply: false
---

Use the `keyenv` CLI for secrets management. Key commands:
- `keyenv pull` - Pull secrets to .env
- `keyenv push` - Push .env to server
- `keyenv run -- <cmd>` - Run with injected secrets
- `keyenv set KEY VALUE` - Set a secret
- `keyenv get KEY` - Get a secret
- `keyenv diff` - Compare local vs remote
- `keyenv scan` - Scan for hardcoded secrets

All commands accept `-e <env>` for environment (default: development) and `--json` for machine-readable output.
```

---

## What Your AI Tool Can Do

Once the skills are installed, your AI coding assistant can:

**Manage secrets conversationally:**
- "Pull the production secrets"
- "Set the DATABASE_URL to postgres://..."
- "What secrets do we have in staging?"
- "Show me the history of the API_KEY"

**Run commands with secrets:**
- "Start the dev server with secrets injected"
- "Run the test suite with production config"

**Scan for security issues:**
- "Scan this repo for hardcoded secrets"
- "Set up a pre-commit hook to prevent secret leaks"

**Manage rotations:**
- "Show me the rotation status for production"
- "Trigger a manual rotation for main_db"

---

## Adding KeyEnv to Your Project Instructions

You can also add KeyEnv instructions directly to your project's AI configuration file.

### CLAUDE.md (Claude Code)

Add to your project's `CLAUDE.md`:

```markdown
## Secrets Management

This project uses KeyEnv for secrets management.

- Pull secrets: `keyenv pull -e <environment>`
- Run with secrets: `keyenv run -- <command>`
- Default environment: development
- Never commit .env files
```

### AGENTS.md (Codex)

Add to your project's `AGENTS.md`:

```markdown
## Environment Variables

Use the `keyenv` CLI to manage secrets. Run `keyenv pull` to sync,
or `keyenv run -- <cmd>` to inject secrets without writing .env files.
```

---

## LLM-Friendly Documentation

KeyEnv provides machine-readable documentation for AI tools:

| File | URL | Purpose |
|------|-----|---------|
| `llms.txt` | [keyenv.dev/llms.txt](https://keyenv.dev/llms.txt) | Index of every docs page, product page, and blog post, with descriptions |
| `llms-full.txt` | [keyenv.dev/llms-full.txt](https://keyenv.dev/llms-full.txt) | The complete documentation as one markdown file |
| `openapi.yaml` | [keyenv.dev/openapi.yaml](https://keyenv.dev/openapi.yaml) | Machine-readable REST API specification |
| `openapi.json` | [keyenv.dev/openapi.json](https://keyenv.dev/openapi.json) | The same specification as JSON |

The first two follow the [llms.txt standard](https://llmstxt.org/). All four are regenerated from the docs and the OpenAPI spec on every build, so they never fall behind the site.

### Raw markdown for any page

Append `.md` to any documentation URL to get the markdown source instead of rendered HTML. This is cheaper for an agent to read and keeps tables and code blocks intact:

```bash
curl https://keyenv.dev/docs/cli.md
curl https://keyenv.dev/docs/getting-started/first-project.md
curl https://keyenv.dev/docs/api/secrets.md
```

Every page also advertises its markdown twin in the HTML head:

```html
<link rel="alternate" type="text/markdown" href="https://keyenv.dev/docs/cli.md" />
```

---

## Security Notes

AI coding assistants interact with KeyEnv through the CLI, which means:

- **Authentication is local.** Your AI tool uses your existing CLI session. No credentials are shared with AI providers.
- **Secrets stay local.** Values fetched by `keyenv get` or `keyenv pull` remain on your machine.
- **Audit trail preserved.** All operations are logged in the KeyEnv audit log, attributed to your user account.
- **Permissions enforced.** The AI tool has the same access level as your CLI session. Environment permissions still apply.
