Synopsis
Description
capy add records a new value for each supplied environment-variable name. In a terminal it prompts for the values. With --web, it collects them in a local browser page. It writes encrypted values to .env and syncs them to the active secret branch by default.
When standard input is piped and --web is absent, capy add accepts exactly one variable name and reads its value from standard input. This is the safe non-interactive form because the secret is not part of the command line. An existing name requires --force in piped mode.
Use --no-push to update .env without syncing. --non-tty without piped input or --web refuses because there is no value source to prompt from.
Flags
See also
Last modified on October 2, 2026