KeyEnvKeyEnv
SDKs & Integrations

API Reference

Complete REST API documentation for KeyEnv

API Reference

The KeyEnv API is a RESTful HTTP API that provides programmatic access to manage projects, environments, secrets, teams, and service tokens.

Base URL

https://api.keyenv.dev

Authentication

The API supports two authentication methods:

Bearer Token (JWT)

For web app and CLI authentication using Clerk-issued JWTs:

Authorization: Bearer <jwt-token>

Service Token

For CI/CD and programmatic access, use service tokens (prefixed with env_):

Authorization: Bearer env_<token>

Service tokens have scoped access to specific projects and environments with read and/or write permissions.

Rate Limiting

API requests are rate limited to 60 requests per minute per user/token.

Rate limit headers are included in responses:

HeaderDescription
X-RateLimit-LimitMaximum requests per minute
X-RateLimit-RemainingRemaining requests in current window
X-RateLimit-ResetUnix timestamp when the limit resets

Error Handling

All errors follow a consistent format:

{
  "error": "Human-readable error message"
}

Common HTTP status codes:

CodeDescription
400Bad request - invalid input
401Unauthorized - missing or invalid authentication
403Forbidden - insufficient permissions
404Resource not found
409Conflict - resource already exists
429Rate limit exceeded
500Internal server error

OpenAPI Specification

The complete OpenAPI specification is published alongside these docs:

Import either file into Swagger Editor, Postman, Insomnia, or an AI agent to explore the API programmatically.

The API Reference section documents every endpoint, parameter, and response schema. It is generated from this specification, so it never drifts from the running API.

Key Endpoints

Health Check

GET /health

Returns API health status. No authentication required.

Projects

MethodEndpointDescription
GET/api/v1/projectsList all projects
POST/api/v1/projectsCreate a project
GET/api/v1/projects/{id}Get a project
PATCH/api/v1/projects/{id}Update a project
DELETE/api/v1/projects/{id}Delete a project

Environments

MethodEndpointDescription
GET/api/v1/projects/{id}/environmentsList environments
POST/api/v1/projects/{id}/environmentsCreate an environment
GET/api/v1/projects/{id}/environments/{env}Get an environment
DELETE/api/v1/projects/{id}/environments/{env}Delete an environment

Secrets

MethodEndpointDescription
GET/api/v1/projects/{id}/environments/{env}/secretsList secrets
POST/api/v1/projects/{id}/environments/{env}/secretsCreate a secret
GET/api/v1/projects/{id}/environments/{env}/secrets/{key}Get a secret
PUT/api/v1/projects/{id}/environments/{env}/secrets/{key}Update a secret
DELETE/api/v1/projects/{id}/environments/{env}/secrets/{key}Delete a secret
GET/api/v1/projects/{id}/environments/{env}/secrets/exportExport secrets (JSON)
POST/api/v1/projects/{id}/environments/{env}/secrets/bulkBulk import

Service Tokens

MethodEndpointDescription
GET/api/v1/tokensList tokens
POST/api/v1/tokensCreate a token
DELETE/api/v1/tokens/{id}Delete a token
POST/api/v1/tokens/{id}/rotateRotate a token

Permissions

MethodEndpointDescription
GET/api/v1/projects/{id}/my-permissionsGet my permissions
GET/api/v1/projects/{id}/environments/{env}/permissionsList permissions
PUT/api/v1/projects/{id}/environments/{env}/permissions/{userId}Set permission
DELETE/api/v1/projects/{id}/environments/{env}/permissions/{userId}Delete permission

Teams

MethodEndpointDescription
GET/api/v1/teamsList teams
POST/api/v1/teamsCreate a team
GET/api/v1/teams/{id}Get a team
POST/api/v1/teams/{id}/membersInvite a member
DELETE/api/v1/teams/{id}/members/{userId}Remove a member

Audit Logs

Requires team admin role. Regular members receive 403 Forbidden.

MethodEndpointDescription
GET/api/v1/auditList audit logs (admin only)
GET/api/v1/teams/{id}/auditList team audit logs (admin only)

Additional Endpoints

The API also includes endpoints for:

  • Billing & Usage: /api/v1/teams/{id}/usage, /api/v1/teams/{id}/billing - Team usage metrics and billing information
  • Team Invitations: /api/v1/teams/{id}/invitations - Manage pending team invitations
  • Account Management: /api/v1/account, /api/v1/account/data-export - Account settings and data export
  • Secret Rotations: /api/v1/rotations/ - Configure automatic secret rotation
  • CLI Authentication: /api/v1/auth/cli/ - Device authorization flow for CLI login

Refer to the OpenAPI specification for complete endpoint documentation.

Example: List Secrets

curl -X GET "https://api.keyenv.dev/api/v1/projects/{projectId}/environments/production/secrets" \
  -H "Authorization: Bearer env_your_token_here"

Response:

{
  "data": [
    {
      "id": "550e8400-e29b-41d4-a716-446655440000",
      "key": "DATABASE_URL",
      "value": "postgres://...",
      "version": 3,
      "created_at": "2024-01-15T10:30:00Z",
      "updated_at": "2024-01-20T14:45:00Z"
    },
    {
      "id": "550e8400-e29b-41d4-a716-446655440001",
      "key": "API_KEY",
      "value": "sk_live_...",
      "version": 1,
      "inherited_from": "development",
      "created_at": "2024-01-15T10:30:00Z",
      "updated_at": "2024-01-15T10:30:00Z"
    }
  ]
}

Example: Create a Secret

curl -X POST "https://api.keyenv.dev/api/v1/projects/{projectId}/environments/production/secrets" \
  -H "Authorization: Bearer env_your_token_here" \
  -H "Content-Type: application/json" \
  -d '{
    "key": "NEW_SECRET",
    "value": "secret_value_here"
  }'

Response:

{
  "data": {
    "id": "550e8400-e29b-41d4-a716-446655440002",
    "key": "NEW_SECRET",
    "version": 1,
    "created_at": "2024-01-21T09:00:00Z",
    "updated_at": "2024-01-21T09:00:00Z"
  }
}

Example: Export Secrets

The export endpoint returns secrets in JSON format:

curl -X GET "https://api.keyenv.dev/api/v1/projects/{projectId}/environments/production/secrets/export" \
  -H "Authorization: Bearer env_your_token_here"

Response:

{
  "data": [
    {
      "key": "DATABASE_URL",
      "value": "postgres://user:pass@localhost:5432/db"
    },
    {
      "key": "API_KEY",
      "value": "sk_live_abc123"
    },
    {
      "key": "REDIS_URL",
      "value": "redis://localhost:6379",
      "inherited_from": "development"
    }
  ]
}

The inherited_from field is present when a secret is inherited from a parent environment.

External Secrets Operator (ESO)

KeyEnv provides ESO-compatible webhook endpoints for Kubernetes integration:

MethodEndpointDescription
GET/api/v1/eso/secretGet single secret
GET/api/v1/eso/secretsGet all secrets (for dataFrom)

See the Kubernetes ESO Integration Guide for setup instructions.

SDKs

For easier integration, use our official SDKs:

The SDKs handle authentication, error handling, and provide type-safe interfaces to the API.

On this page