Skip to main content
Run capy in the project first to finish setup. Then check the active secret branch with capy branch. The commands below add values to that branch.

Add from your terminal

Pass variable names, not their values:
Enter each value when prompted. Capy encrypts the values, writes them to .env, and syncs them to Capy by default. You do not need a separate capy push after a successful addition.

Add in your browser

To enter the values in a local browser page instead:
Complete the browser form and leave the CLI running until it finishes. Use --no-open if you want the CLI to print the page URL without opening it automatically.

Add from another command

Pipe a single value into a single variable name when another program produces the secret:
Replace command-that-produces-the-value with your actual producer. This keeps the value out of Capy’s command-line arguments. The JSON result reports the operation without printing the value. An existing name is refused unless you pass --force; use capy edit when you intend to update an existing secret.

Save locally before sharing

Add --no-push to write the encrypted value to .env without syncing it yet:
Review and commit any resulting keep.lock changes with your project. Keep .env gitignored.

Check the result

This lists variable names and connector metadata without exposing values. Your application can read the new value when you launch it with capy run. capy add requires a cloud or BYOC project; it is unavailable in local-only mode.

See also

Last modified on October 2, 2026