NEW DEV IN 10 SECONDS

Envault.Fast developer onboarding for environment variables

STOP PASSING .ENV FILES AROUND.
RUN `ENVAULT LOGIN` THEN `ENVAULT PULL`.
ONBOARD NEW DEVS IN ABOUT 10 SECONDS.

$ curl -fsSL https://raw.githubusercontent.com/DinanathDash/Envault/main/install.sh | sh

DESIGN PARTNER PROGRAM

FREE TIER FOR AGENCIES AND STARTUPS THAT WANT TO STRESS TEST ENVAULT.

Break our CLI. Probe GitHub JIT. Try to bypass HITL.

From zero setup to synced secrets
in about 10 seconds.

LINK. LOGIN. PULL. SHIP.
BUILT FOR DAILY DEVELOPER ONBOARDING.

DeveloperPush Secrets
LocalDevelopment
CI/CDPipeline
ENVAULTSecure Hub
StagingTesting
TeamCollaborate
ProductionDeploy
Validate
Encrypt
Rotate

Connect Repo Once

Project owners run `envault init`, choose a default environment (for example `development`), and commit `envault.json` so the repo is linked and teammates can pull without `--env` flags.

Login And Pull

A new teammate runs `envault login` then `envault pull` inside the repo. No `.env` handoff, no manual copy/paste.

Stress-Test The Guardrails

Design partners get free access to hammer CLI flows, GitHub JIT auto-provisioning, and HITL approval fencing with direct feedback loops to our team.

0s
Onboarding Flow
0
Core Commands
5-10
Design Partners
$0
Program Cost
Command Line Interface

Onboard developers with two commands.

ENVAULT LOGIN. ENVAULT PULL.
GITHUB JIT CHECKS REPO COLLABORATORS AND UNLOCKS VIEW ACCESS INSTANTLY.

GitHub JIT Onboarding

Link the repo once, then collaborators get Viewer access automatically when they run `envault pull` in that workspace.

Smart Environment Selection

Default environment selection during `init` and automatic context-aware command execution. No more manual flag juggling.

Secure Device Flow

Authenticate securely via browser without handling long-lived tokens manually. Multi-environment aware authentication.

v1.38.0 released
zsh - 80 x 24
~$

Built for fast onboarding loops.

CORE CAPABILITIES USERS SHOULD KNOW BEFORE READING THE DOCS

Build With CLI, SDK, And MCP

Use one secret model across terminal workflows, TypeScript services, and AI agent tooling.

Open Agent Runtime Surface

The cloud control plane is proprietary, but agent execution code is MIT-licensed so teams can inspect runtime behavior directly.

Audit HITL + Delegated JWT Flow

The MIT-licensed MCP and SDK code lets you verify envault_agt_ short-lived token gating and approval-first mutation behavior.

SDK v1.10.0 / MCP v1.12.0

Built For Fast Daily Use

LOGIN / PULL / RUN / SHIP

[SPEC_01]

END-TO-END ENCRYPTION

AES-256-GCM

Secrets are encrypted before they leave your machine, then decrypted locally in CLI workflows.

[SPEC_02]

PASSWORDLESS AUTH

PASSKEY + OAUTH

Use passkeys and OAuth so teammates can authenticate quickly without password resets or token juggling.

[SPEC_03]

GITHUB-INTEGRATED ACCESS

MULTI-ACCOUNT READY

Link one repo and let GitHub collaborator status drive JIT access during `envault pull`.

[SPEC_04]

ENVIRONMENT-SCOPED PERMISSIONS

LEAST PRIVILEGE

Gate read/write access by environment so teams move fast without exposing every key to every person.

[SPEC_05]

REAL-TIME SYNC RELIABILITY

HYBRID REFRESH

Realtime plus focus-aware refresh keeps your local and dashboard views in sync while you ship.

[SPEC_06]

ACCOUNT LIFECYCLE SAFETY

SOFT DELETE + RECOVERY

Recovery windows and controlled purge flows help teams recover from bad deletes without chaos.

Teams Replacing `.env` Slack Threads

Direct feedback from developers using Envault in day-to-day shipping workflows

"Used to rely on a shared 1Password vault for .env files. Absolute nightmare when someone left the company. Envault handles the rotation so I don't have to panic every time a junior dev quits. Does exactly what it says on the tin."

Karthik Iyer

Karthik Iyer

Lead Backend Engineer at PayStream

"Look, HashiCorp Vault is great, but managing it is a full-time job. Envault gave us exactly what we needed without the infrastructure headache. It took my team maybe 10 minutes to migrate. The CLI is solid and gets out of your way."

Rohan Desai

Rohan Desai

DevOps Lead at FinStack

"We outgrew GitHub Secrets, and AWS Secrets Manager was too clunky for our frontend team. Envault sits in the middle and gets out of the way."

Marcus Thorne

Marcus Thorne

Site Reliability Engineer at Vantage

Design Partner Program

Help us break Envault.

WE ARE LOOKING FOR 5-10 FAST-MOVING DEV AGENCIES AND STARTUPS TO STRESS-TEST OUR CLI AND GITHUB JIT WORKFLOWS IN PRODUCTION. IN EXCHANGE, YOU GET ENVAULT FREE FOREVER.