Skip to main content
Capy’s runtime story is one command: capy run -- <your command>. It wraps any process, decrypts your secrets in memory, and hands the plaintext values to the child as ordinary environment variables. Your app reads process.env (or os.environ, or ENV[...], or whatever your language uses) - no library to import, no SDK per language.

The pattern

Capy:
  1. Picks a mode from process.env. Either _SECRETS_BLOB with _PROJECT_KEY or the legacy SECRETS_BLOB with PROJECT_KEY enables deployed mode. Each pair must be complete; a half-configured pair is an error.
  2. Local mode reads .env from the current directory. It resolves the project key through the Capy service on a cloud or BYOC profile, or from the local key on a local-only profile. Deployed mode parses the selected blob, fetches its service key, and combines it with the matching project key.
  3. Decrypts every capy:… snippet in .env (local mode), or the whole encrypted env map (deployed mode).
  4. Spawns the child with the decrypted values set in its environment.
  5. Forwards SIGINT, SIGTERM, and SIGHUP to the child; exits with the child’s exit code.
Deployed mode, and local mode on a cloud or BYOC profile, contact the Capy service once at startup to authorize the decryption, then never again for the life of the process. A local-only profile is the exception: it resolves the key entirely offline, prompting for your passphrase if the session is locked. See capy run for what each mode needs. Plaintext values are passed to the child process. In deployed mode, Capy may also write .capy/next-env.js; that generated module contains variable names and process.env lookups, not plaintext values.

Examples

In package.json scripts

Put capy run in your scripts once and forget about it:
Then bun run dev / npm run dev / pnpm dev all work as usual; the wrapping is invisible.

Precedence: shell env vs. decrypted values

The rule differs between the two modes:
  • Local mode. Plaintext keys in .env follow dotenv’s usual precedence — a variable already set in your shell wins over the file. Encrypted capy:… values are the exception: they’re re-applied after that merge, so a decrypted project secret always overrides a same-named variable inherited from your shell.
  • Deployed mode with _SECRETS_BLOB / _PROJECT_KEY. Decrypted values override same-named values already in the environment.
  • Deployed mode with SECRETS_BLOB / PROJECT_KEY. Existing environment values override decrypted values. This is the pair emitted by the token-and-instructions flow.

What’s next

Deploying

How the runtime key source gets set in production.

capy run (CLI reference)

Mode detection, precedence, and behavior details.
Last modified on October 2, 2026