Skip to main content
By the end of this page your .env is end-to-end encrypted, shared with your team, and ready to deploy from a Node.js app. Five commands.
1

Install the CLI

Capy is a single CLI - no daemon, no background service.
2

Sync your secrets

From any project that has a .env:
On the first run, Capy authenticates you, creates or selects a project, encrypts every value in your .env, and uploads ciphertext. It rewrites .env with capy:… snippets and creates keep.lock. Commit keep.lock; it is the project manifest and does not contain plaintext values or keys.Run capy again whenever you want to pull or push changes.
3

Invite a teammate

Capy prints a one-line redeem code. Send it out-of-band. They run capy redeem <code> and now share access - no key material ever touches Capy’s backend in plaintext.
4

Run your app

Wrap your command with capy run:
Capy decrypts .env in memory and spawns your process with plaintext values available as process.env. Your code reads env vars the standard way - no library to import:
Add it to your package.json scripts and forget it:
5

Deploy

Configure a saved deploy target for Cloudflare Workers, Cloudflare Pages, Vercel, AWS SSM, or Dokploy. For a platform you configure yourself, choose the token path and set SECRETS_BLOB and PROJECT_KEY together; then use capy run -- node server.js as the process entrypoint. See Deploying for target and token behavior.
That’s the whole loop. Edit a secret locally, run capy, redeploy. Anyone you’ve invited stays in sync. Anyone you’ve kicked loses access immediately, with no re-encryption needed.

What’s next

How it works

The full cryptographic design.

CLI Reference

Every command, every flag.
Last modified on October 2, 2026