Skip to main content
capy run has you covered. It decrypts .env in memory and spawns your command with the plaintext values injected as environment variables. It works with anything that reads env vars - PHP, Elixir, Java, .NET, Deno, Bun, static binaries, shell scripts.

The pattern

On your own machine, Capy:
  1. Reads the local .env file.
  2. Decrypts every capy:… snippet using your project key.
  3. Spawns the child process with the decrypted values in its environment.
  4. Forwards signals (SIGINT, SIGTERM, SIGHUP) and exits with the child’s exit code.
The plaintext lives only in the child process’s memory - never on disk.

Examples

In containers

capy run works as a container entrypoint when SECRETS_BLOB and PROJECT_KEY are both set. In that mode it decrypts the blob instead of reading .env and contacts the Capy service at startup. The pair must be complete; a half-configured pair exits with an error. See Deploying for target and token setup.

What’s next

Running your app

Signals, exit codes, and env precedence in detail.
Last modified on October 2, 2026