npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

getmyenv

v0.9.5

Published

CLI for getmyenv, an encrypted store for environment variables and secrets. We store ciphertext only.

Readme

getmyenv

Keep using environment variables. Stop managing them as files.

getmyenv is an encrypted store for environment variables and secrets. Use it from the dashboard or with npx getmyenv. We store ciphertext only.

cd your-project
npx getmyenv                          # Start without an account, or Sign in
npx getmyenv import                   # encrypt and upload your .env
npx getmyenv run -- npm run dev       # start with the default context
npx getmyenv run staging -- npm start # or pick one

Commands

  • getmyenv: setup in a new folder, status in a linked one. Without a TTY it prints next steps and exits.
  • run [context] -- <cmd>: resolve, validate, merge, spawn. A missing value stops the run and prints its name (--allow-missing to run anyway). getmyenv values replace the parent env and replaced names are printed (--keep-existing to keep parent values). --explain lists names and origins, never values.
  • status: project, token, contexts and the run command.
  • context list | create "<name>" [--from <slug>] [--use] | use <slug>
  • set KEY[=VALUE]... [--expires <date|never>], set KEY --stdin, unset KEY... [--all], ls
  • import [file] [--prune] [--dry-run] [--yes]: .env.<slug> goes to that context.
  • export [-o file | --stdout] [--yes]: for tools that need a file. The file is added to .gitignore and gets owner-only permissions on macOS and Linux.
  • guest [--name <name>]: a project without an account. It works for 30 days. Claim it within 60.
  • claim: claim a guest project. Reads .getmyenv/claim.json, or asks for the claim code and guest passphrase that guest printed once.
  • backup [-o file]: encrypted backup of open contexts (default <project>.getmyenv-backup). It opens with the Vault password in effect when it was made.
  • restore <file> [--dry-run] [--yes]: restore a backup into this folder's project. Values go into open contexts with the same slug and replace values with the same name. Read-only and missing contexts are skipped.
  • start: same as bare getmyenv. start --template <id or link> adds a template's variable names and asks for each value.
  • lock: forget every unlocked context key on this machine. unlink [--yes], help [command]

run, set, unset, ls, import and export take -c, --context <slug>. The default is the server token's context, then context in .getmyenv/project.json, then development. Every command takes --api-url <url>.

Prompts and status lines go to stderr, so export --stdout > .env stays clean.

Commit .getmyenv/project.json. token.json and claim.json stay local and are gitignored.

Output of npx getmyenv --help (0.9.5):

Usage: getmyenv [options] [command]

Keep using environment variables. Stop managing them as files.

Options:
  -V, --version               output the version number
  --api-url <url>             API base URL
  -h, --help                  display help for command

Commands:
  start [options]             Set up this folder (same as bare npx getmyenv).
                              Status when already linked.
  run [options] [context]     Run a command with a context's variables in its
                              environment
  status [options]            Show project, token, contexts and the run command
  context                     List, create or pick contexts
  set [options] <pairs...>    Set values: set KEY=VALUE, or set KEY to be
                              prompted
  unset [options] <names...>  Remove values from a context
  ls [options]                Variable names by context with status (never
                              values)
  import [options] [file]     Encrypt a .env file and upload it (.env.<slug>
                              goes to that context)
  export [options]            Write a context to a plaintext .env file, for
                              tools that need one
  guest [options]             Create a guest project without an account. It
                              works for 30 days. Claim it within 60.
  claim [options]             Claim a guest project (reads .getmyenv/claim.json,
                              or asks for the claim code)
  backup [options]            Write an encrypted backup of open contexts
  restore [options] <file>    Restore a backup into this folder's project (open
                              contexts with the same slug)
  lock [options]              Forget every unlocked context key on this machine
                              (OS keychain)
  unlink [options]            Revoke this folder's token and remove local
                              .getmyenv files
  help [command]              display help for command

Environment:
  GETMYENV_TOKEN          Token for CI and servers (instead of .getmyenv/token.json). A server token holds its context key.
  GETMYENV_API_URL        API base URL (https, or http://localhost)
  GETMYENV_CONFIG_DIR     Machine identity and cache dir (default ~/.config/getmyenv)
  GETMYENV_SKIP_UPDATE    Set to 1 to skip the update notice
  GETMYENV_KEYCHAIN       Set to 0 to always ask for the Vault password
  GETMYENV_MACHINE_LABEL  Name shown for this machine in access requests

Vault password

Each context has its own key, sealed to your account. Your Vault password opens your account key. For open contexts, after you enter the Vault password in a terminal, the unlocked context keys stay in your OS keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service) for 8 hours. The password is never stored.

  • npx getmyenv lock removes every entry. unlink removes this project's.
  • Server tokens hold their context key and never ask.
  • Guest projects unlock with the passphrase in .getmyenv/claim.json and never ask.
  • GETMYENV_KEYCHAIN=0 always asks.

CI and servers

Create a server token for one context on the dashboard CLI page. It holds that context's key.

export GETMYENV_TOKEN=...   # server token from the dashboard
npx getmyenv run -- node server.js

Server tokens are read-only. set needs the folder token from browser sign-in, or a guest project. printf %s "$VALUE" | npx getmyenv set API_KEY --stdin keeps the value out of argv.

  • GETMYENV_TOKEN: a token from the dashboard CLI page.
  • GETMYENV_CONFIG_DIR: machine key and cache (default ~/.config/getmyenv). Use a persistent volume in containers.
  • GETMYENV_API_URL: API origin. https only, http for localhost.
  • GETMYENV_MACHINE_LABEL: the machine name shown in approval requests.
  • GETMYENV_SKIP_UPDATE=1: skip the update notice.
  • GETMYENV_KEYCHAIN=0: never use the OS keychain.
  • The update check and the keychain are skipped when CI is set (unless it is false or 0).

Open and Read-only

  • Open contexts: the CLI can read and write. Browser sign-in gives the folder a token in .getmyenv/token.json.
  • Read-only contexts: the CLI can read and export, never write. Only the owner sets Read-only values, in the dashboard. Use a server token from Project settings, Tokens (one context, IP allowlist) with GETMYENV_TOKEN. Each server token has a new machines rule: ask you on Requests (default), trust machines from its allowed IPs on first read (each entry /24 or narrower, IPv6 /64), or block them. Trusted machines read without asking. status shows the rule.

Chaining

op run -- npx getmyenv run staging -- npm start

License: MIT (see LICENSE). The hosted service at getmyenv.com has its own Terms.

See https://getmyenv.com/docs