getmyenv
v0.9.5
Published
CLI for getmyenv, an encrypted store for environment variables and secrets. We store ciphertext only.
Maintainers
Readme
getmyenv
Keep using environment variables. Stop managing them as files.
getmyenv is an encrypted store for environment variables and secrets. Use it from the dashboard or with npx getmyenv. We store ciphertext only.
cd your-project
npx getmyenv # Start without an account, or Sign in
npx getmyenv import # encrypt and upload your .env
npx getmyenv run -- npm run dev # start with the default context
npx getmyenv run staging -- npm start # or pick oneCommands
getmyenv: setup in a new folder, status in a linked one. Without a TTY it prints next steps and exits.run [context] -- <cmd>: resolve, validate, merge, spawn. A missing value stops the run and prints its name (--allow-missingto run anyway). getmyenv values replace the parent env and replaced names are printed (--keep-existingto keep parent values).--explainlists names and origins, never values.status: project, token, contexts and the run command.context list | create "<name>" [--from <slug>] [--use] | use <slug>set KEY[=VALUE]... [--expires <date|never>],set KEY --stdin,unset KEY... [--all],lsimport [file] [--prune] [--dry-run] [--yes]:.env.<slug>goes to that context.export [-o file | --stdout] [--yes]: for tools that need a file. The file is added to.gitignoreand gets owner-only permissions on macOS and Linux.guest [--name <name>]: a project without an account. It works for 30 days. Claim it within 60.claim: claim a guest project. Reads.getmyenv/claim.json, or asks for the claim code and guest passphrase thatguestprinted once.backup [-o file]: encrypted backup of open contexts (default<project>.getmyenv-backup). It opens with the Vault password in effect when it was made.restore <file> [--dry-run] [--yes]: restore a backup into this folder's project. Values go into open contexts with the same slug and replace values with the same name. Read-only and missing contexts are skipped.start: same as baregetmyenv.start --template <id or link>adds a template's variable names and asks for each value.lock: forget every unlocked context key on this machine.unlink [--yes],help [command]
run, set, unset, ls, import and export take -c, --context <slug>. The default is the server token's context, then context in .getmyenv/project.json, then development. Every command takes --api-url <url>.
Prompts and status lines go to stderr, so export --stdout > .env stays clean.
Commit .getmyenv/project.json. token.json and claim.json stay local and are gitignored.
Output of npx getmyenv --help (0.9.5):
Usage: getmyenv [options] [command]
Keep using environment variables. Stop managing them as files.
Options:
-V, --version output the version number
--api-url <url> API base URL
-h, --help display help for command
Commands:
start [options] Set up this folder (same as bare npx getmyenv).
Status when already linked.
run [options] [context] Run a command with a context's variables in its
environment
status [options] Show project, token, contexts and the run command
context List, create or pick contexts
set [options] <pairs...> Set values: set KEY=VALUE, or set KEY to be
prompted
unset [options] <names...> Remove values from a context
ls [options] Variable names by context with status (never
values)
import [options] [file] Encrypt a .env file and upload it (.env.<slug>
goes to that context)
export [options] Write a context to a plaintext .env file, for
tools that need one
guest [options] Create a guest project without an account. It
works for 30 days. Claim it within 60.
claim [options] Claim a guest project (reads .getmyenv/claim.json,
or asks for the claim code)
backup [options] Write an encrypted backup of open contexts
restore [options] <file> Restore a backup into this folder's project (open
contexts with the same slug)
lock [options] Forget every unlocked context key on this machine
(OS keychain)
unlink [options] Revoke this folder's token and remove local
.getmyenv files
help [command] display help for command
Environment:
GETMYENV_TOKEN Token for CI and servers (instead of .getmyenv/token.json). A server token holds its context key.
GETMYENV_API_URL API base URL (https, or http://localhost)
GETMYENV_CONFIG_DIR Machine identity and cache dir (default ~/.config/getmyenv)
GETMYENV_SKIP_UPDATE Set to 1 to skip the update notice
GETMYENV_KEYCHAIN Set to 0 to always ask for the Vault password
GETMYENV_MACHINE_LABEL Name shown for this machine in access requestsVault password
Each context has its own key, sealed to your account. Your Vault password opens your account key. For open contexts, after you enter the Vault password in a terminal, the unlocked context keys stay in your OS keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service) for 8 hours. The password is never stored.
npx getmyenv lockremoves every entry.unlinkremoves this project's.- Server tokens hold their context key and never ask.
- Guest projects unlock with the passphrase in
.getmyenv/claim.jsonand never ask. GETMYENV_KEYCHAIN=0always asks.
CI and servers
Create a server token for one context on the dashboard CLI page. It holds that context's key.
export GETMYENV_TOKEN=... # server token from the dashboard
npx getmyenv run -- node server.jsServer tokens are read-only. set needs the folder token from browser sign-in, or a guest project. printf %s "$VALUE" | npx getmyenv set API_KEY --stdin keeps the value out of argv.
GETMYENV_TOKEN: a token from the dashboard CLI page.GETMYENV_CONFIG_DIR: machine key and cache (default~/.config/getmyenv). Use a persistent volume in containers.GETMYENV_API_URL: API origin. https only, http for localhost.GETMYENV_MACHINE_LABEL: the machine name shown in approval requests.GETMYENV_SKIP_UPDATE=1: skip the update notice.GETMYENV_KEYCHAIN=0: never use the OS keychain.- The update check and the keychain are skipped when
CIis set (unless it isfalseor0).
Open and Read-only
- Open contexts: the CLI can read and write. Browser sign-in gives the folder a token in
.getmyenv/token.json. - Read-only contexts: the CLI can read and export, never write. Only the owner sets Read-only values, in the dashboard. Use a server token from Project settings, Tokens (one context, IP allowlist) with
GETMYENV_TOKEN. Each server token has a new machines rule: ask you on Requests (default), trust machines from its allowed IPs on first read (each entry /24 or narrower, IPv6 /64), or block them. Trusted machines read without asking.statusshows the rule.
Chaining
op run -- npx getmyenv run staging -- npm startLicense: MIT (see LICENSE). The hosted service at getmyenv.com has its own Terms.
See https://getmyenv.com/docs
