Envault.Fast developer onboarding for environment variables
STOP PASSING .ENV FILES AROUND.
RUN `ENVAULT LOGIN` THEN `ENVAULT PULL`.
ONBOARD NEW DEVS IN ABOUT 10 SECONDS.
$ curl -fsSL https://raw.githubusercontent.com/DinanathDash/Envault/main/install.sh | shDESIGN PARTNER PROGRAM
FREE TIER FOR AGENCIES AND STARTUPS THAT WANT TO STRESS TEST ENVAULT.
From zero setup to synced secrets
in about 10 seconds.
LINK. LOGIN. PULL. SHIP.
BUILT FOR DAILY DEVELOPER ONBOARDING.
Connect Repo Once
Project owners run `envault init`, choose a default environment (for example `development`), and commit `envault.json` so the repo is linked and teammates can pull without `--env` flags.
Login And Pull
A new teammate runs `envault login` then `envault pull` inside the repo. No `.env` handoff, no manual copy/paste.
Stress-Test The Guardrails
Design partners get free access to hammer CLI flows, GitHub JIT auto-provisioning, and HITL approval fencing with direct feedback loops to our team.
Onboard developers with two commands.
ENVAULT LOGIN. ENVAULT PULL.
GITHUB JIT CHECKS REPO COLLABORATORS AND UNLOCKS VIEW ACCESS INSTANTLY.
GitHub JIT Onboarding
Link the repo once, then collaborators get Viewer access automatically when they run `envault pull` in that workspace.
Smart Environment Selection
Default environment selection during `init` and automatic context-aware command execution. No more manual flag juggling.
Secure Device Flow
Authenticate securely via browser without handling long-lived tokens manually. Multi-environment aware authentication.
Built for fast onboarding loops.
CORE CAPABILITIES USERS SHOULD KNOW BEFORE READING THE DOCS
Build With CLI, SDK, And MCP
Use one secret model across terminal workflows, TypeScript services, and AI agent tooling.
Open Agent Runtime Surface
The cloud control plane is proprietary, but agent execution code is MIT-licensed so teams can inspect runtime behavior directly.
Audit HITL + Delegated JWT Flow
The MIT-licensed MCP and SDK code lets you verify envault_agt_ short-lived token gating and approval-first mutation behavior.
Built For Fast Daily Use
LOGIN / PULL / RUN / SHIP
END-TO-END ENCRYPTION
Secrets are encrypted before they leave your machine, then decrypted locally in CLI workflows.
PASSWORDLESS AUTH
Use passkeys and OAuth so teammates can authenticate quickly without password resets or token juggling.
GITHUB-INTEGRATED ACCESS
Link one repo and let GitHub collaborator status drive JIT access during `envault pull`.
ENVIRONMENT-SCOPED PERMISSIONS
Gate read/write access by environment so teams move fast without exposing every key to every person.
REAL-TIME SYNC RELIABILITY
Realtime plus focus-aware refresh keeps your local and dashboard views in sync while you ship.
ACCOUNT LIFECYCLE SAFETY
Recovery windows and controlled purge flows help teams recover from bad deletes without chaos.
Teams Replacing `.env` Slack Threads
Direct feedback from developers using Envault in day-to-day shipping workflows
"Used to rely on a shared 1Password vault for .env files. Absolute nightmare when someone left the company. Envault handles the rotation so I don't have to panic every time a junior dev quits. Does exactly what it says on the tin."
Karthik Iyer
Lead Backend Engineer at PayStream
"Look, HashiCorp Vault is great, but managing it is a full-time job. Envault gave us exactly what we needed without the infrastructure headache. It took my team maybe 10 minutes to migrate. The CLI is solid and gets out of your way."
Rohan Desai
DevOps Lead at FinStack
"We outgrew GitHub Secrets, and AWS Secrets Manager was too clunky for our frontend team. Envault sits in the middle and gets out of the way."
Marcus Thorne
Site Reliability Engineer at Vantage
"Used to rely on a shared 1Password vault for .env files. Absolute nightmare when someone left the company. Envault handles the rotation so I don't have to panic every time a junior dev quits. Does exactly what it says on the tin."
Karthik Iyer
Lead Backend Engineer at PayStream
"Look, HashiCorp Vault is great, but managing it is a full-time job. Envault gave us exactly what we needed without the infrastructure headache. It took my team maybe 10 minutes to migrate. The CLI is solid and gets out of your way."
Rohan Desai
DevOps Lead at FinStack
"We outgrew GitHub Secrets, and AWS Secrets Manager was too clunky for our frontend team. Envault sits in the middle and gets out of the way."
Marcus Thorne
Site Reliability Engineer at Vantage
"Juggling 10 different client projects and keeping their env vars straight used to break my brain. Dropped Envault into my workflow last month. Now I just `envault run npm run dev` and it pulls the right keys. Simple, stupid, works."
Ananya Desai
Freelance Full-Stack at Self-employed
"If I catch one more dev pasting production database URIs into Slack, I'm going to lose it. Envault fixed our onboarding. New hires get access instantly, and we revoke it just as fast. It's infrastructure I don't have to build myself."
Vikram Singh
Co-founder & CTO at SynthAI
"I usually hate adding new tools to our stack, but Envault actually solves a real problem. Hooked it up to our microservices and it handles the secrets silently. Giving it 4 stars only because the web dashboard can be a bit sluggish sometimes."
Priya Sharma
Backend Developer at ZeptoNova
"Was skeptical about moving away from Doppler. Envault's UI is cleaner and their client-side decryption model actually checks out. We had a weird edge case with Docker Compose caching, but their support sorted it out in a day. Solid tool."
Tomáš Novák
DevOps Engineer at Shift
"Good tool. Beats writing custom bash scripts to sync vars across Vercel and our custom EC2 instances. The UI is a bit barebones right now, but the CLI does the heavy lifting anyway so I don't really care."
Elena Rostova
Platform Engineer at MetricFlow
"Used to rely on a shared 1Password vault for .env files. Absolute nightmare when someone left the company. Envault handles the rotation so I don't have to panic every time a junior dev quits. Does exactly what it says on the tin."
Karthik Iyer
Lead Backend Engineer at PayStream
"Look, HashiCorp Vault is great, but managing it is a full-time job. Envault gave us exactly what we needed without the infrastructure headache. It took my team maybe 10 minutes to migrate. The CLI is solid and gets out of your way."
Rohan Desai
DevOps Lead at FinStack
"We outgrew GitHub Secrets, and AWS Secrets Manager was too clunky for our frontend team. Envault sits in the middle and gets out of the way."
Marcus Thorne
Site Reliability Engineer at Vantage
"Juggling 10 different client projects and keeping their env vars straight used to break my brain. Dropped Envault into my workflow last month. Now I just `envault run npm run dev` and it pulls the right keys. Simple, stupid, works."
Ananya Desai
Freelance Full-Stack at Self-employed
"If I catch one more dev pasting production database URIs into Slack, I'm going to lose it. Envault fixed our onboarding. New hires get access instantly, and we revoke it just as fast. It's infrastructure I don't have to build myself."
Vikram Singh
Co-founder & CTO at SynthAI
"I usually hate adding new tools to our stack, but Envault actually solves a real problem. Hooked it up to our microservices and it handles the secrets silently. Giving it 4 stars only because the web dashboard can be a bit sluggish sometimes."
Priya Sharma
Backend Developer at ZeptoNova
"Was skeptical about moving away from Doppler. Envault's UI is cleaner and their client-side decryption model actually checks out. We had a weird edge case with Docker Compose caching, but their support sorted it out in a day. Solid tool."
Tomáš Novák
DevOps Engineer at Shift
"Good tool. Beats writing custom bash scripts to sync vars across Vercel and our custom EC2 instances. The UI is a bit barebones right now, but the CLI does the heavy lifting anyway so I don't really care."
Elena Rostova
Platform Engineer at MetricFlow