Skip to main content
Capy encrypts values from your .env, syncs encrypted state, and gives your app ordinary environment variables through capy run. keep.lock is the committed manifest that links a repository to its Capy project. It contains metadata and hashes, never plaintext values or keys. Install the CLI with npm, Bun, or the release installer. The installer selects a native binary for macOS, Linux, and Windows where available, verifies its published checksum when available, and otherwise falls back to npm.

Why teams pick Capy

  • Works through environment variables. Your code keeps reading process.env, os.environ, ENV, or the equivalent in your runtime.
  • Secret branches. Capy branches are separate from Git branches. Switch them with capy checkout <branch>.
  • Reviewable metadata. Commit keep.lock; it records the project and encrypted-value hashes, not values or keys.
  • Local or browser-assisted interaction. Most commands run in the terminal. --web renders supported interactive setup and conflict screens on a local browser page.

Get started

Pick your runtime and be up in under two minutes.

How it works

The cryptographic design behind Capy’s zero-trust model.

Compare

Capy vs. Doppler, Infisical, AWS Secrets Manager, SOPS.

License

What Capy’s AGPL-3.0 license means for your team.
Last modified on October 2, 2026