capy run -- <your command>. It wraps any process, decrypts your secrets in memory, and hands the plaintext values to the child as ordinary environment variables. Your app reads process.env (or os.environ, or ENV[...], or whatever your language uses) - no library to import, no SDK per language.
The pattern
- Picks a mode from
process.env. Either_SECRETS_BLOBwith_PROJECT_KEYor the legacySECRETS_BLOBwithPROJECT_KEYenables deployed mode. Each pair must be complete; a half-configured pair is an error. - Local mode reads
.envfrom the current directory. It resolves the project key through the Capy service on a cloud or BYOC profile, or from the local key on a local-only profile. Deployed mode parses the selected blob, fetches its service key, and combines it with the matching project key. - Decrypts every
capy:…snippet in.env(local mode), or the whole encrypted env map (deployed mode). - Spawns the child with the decrypted values set in its environment.
- Forwards
SIGINT,SIGTERM, andSIGHUPto the child; exits with the child’s exit code.
capy run for what each mode needs.
Plaintext values are passed to the child process. In deployed mode, Capy may also write .capy/next-env.js; that generated module contains variable names and process.env lookups, not plaintext values.
Examples
In package.json scripts
Putcapy run in your scripts once and forget about it:
bun run dev / npm run dev / pnpm dev all work as usual; the wrapping is invisible.
Precedence: shell env vs. decrypted values
The rule differs between the two modes:- Local mode. Plaintext keys in
.envfollow dotenv’s usual precedence — a variable already set in your shell wins over the file. Encryptedcapy:…values are the exception: they’re re-applied after that merge, so a decrypted project secret always overrides a same-named variable inherited from your shell. - Deployed mode with
_SECRETS_BLOB/_PROJECT_KEY. Decrypted values override same-named values already in the environment. - Deployed mode with
SECRETS_BLOB/PROJECT_KEY. Existing environment values override decrypted values. This is the pair emitted by the token-and-instructions flow.
What’s next
Deploying
How the runtime key source gets set in production.
capy run (CLI reference)
Mode detection, precedence, and behavior details.