.env is end-to-end encrypted, shared with your team, and ready to deploy from a Node.js app. Five commands.
1
Install the CLI
2
Sync your secrets
From any project that has a On the first run, Capy authenticates you, creates or selects a project, encrypts every value in your
.env:.env, and uploads ciphertext. It rewrites .env with capy:… snippets and creates keep.lock. Commit keep.lock; it is the project manifest and does not contain plaintext values or keys.Run capy again whenever you want to pull or push changes.3
Invite a teammate
capy redeem <code> and now share access - no key material ever touches Capy’s backend in plaintext.4
Run your app
Wrap your command with Capy decrypts Add it to your
capy run:.env in memory and spawns your process with plaintext values available as process.env. Your code reads env vars the standard way - no library to import:package.json scripts and forget it:5
Deploy
SECRETS_BLOB and PROJECT_KEY together; then use capy run -- node server.js as the process entrypoint. See Deploying for target and token behavior.capy, redeploy. Anyone you’ve invited stays in sync. Anyone you’ve kicked loses access immediately, with no re-encryption needed.
What’s next
How it works
The full cryptographic design.
CLI Reference
Every command, every flag.