capy run around local Next.js commands. It gives Next decrypted values through process.env; no application SDK is required.
1
Install the CLI
2
Sync your secrets
.env, and creates keep.lock. Commit keep.lock; it contains project metadata and hashes, not plaintext values or keys.3
Wrap development commands
4
Choose a deployment path
For Vercel, configure a Vercel target with
capy deploy. The target writes selected values to Vercel and uses a deploy PR, so Vercel reads its normal environment variables; it does not need capy run in the build.For a platform where you control the process, use the token-and-instructions path from capy deploy, set SECRETS_BLOB and PROJECT_KEY together, and wrap the build or start command with capy run. In deployed mode, capy run writes .capy/next-env.js with variable-name lookups so Next can inline selected values at build time.Build-time inlining
When using the runtime-pair path withnext build, capy run writes .capy/next-env.js with every decrypted variable name. Do not export that whole map through Next’s env option: values in that option can be bundled into client-side code. Select only names that are intentionally public, and guard the import because local runs do not create the file.
process.env reads; it does not contain plaintext values. The explicit publicNames list is the security boundary for values Next may inline into browser output. Server-only secrets can still be read from process.env in server-side code, without adding them to env.
Self-hosted Next.js
Use a runtime pair and a wrapped entrypoint:SECRETS_BLOB and PROJECT_KEY must both be present. With neither pair set, capy run uses the local .env and keep.lock in the working directory.
What’s next
Deploying
Target delivery and runtime-pair setup.
Running your app
Local and deployed runtime behavior.