Skip to content
colinguinane1Public

About

The easiest way to manage enviornment variables across your devices.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

16 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

envpull

Secure, client-side encrypted .env sync for developers.

Website: https://envpull.dev · API: https://api.envpull.dev

Install

npm i -g @colinguinane/envpull-cli

Requires Node.js 20+.

Quick start

envpull login          # create an account or sign in
envpull init           # link this directory to a project
envpull push           # encrypt and upload .env
envpull pull           # download and decrypt .env

Forgot your password?

envpull recover        # reset with your recovery key (no login required)

How encryption works

  • Your .env is encrypted on your machine (AES-GCM) before upload.
  • The server stores ciphertext and key wraps only — not plaintext secrets.
  • Unlock uses your password locally (Argon2id). On signup you get a recovery key; save it. envpull cannot restore a vault if both the password and recovery key are lost.
  • Password and recovery key are sent over TLS so the API can authenticate you (they're hashed server-side). Env contents stay client-encrypted.

Useful commands

envpull whoami
envpull logout
envpull config show
envpull config set-api https://api.envpull.dev
envpull config set-biometrics on   # macOS Touch ID unlock

Override the API URL with ENVPULL_API_URL (HTTPS required; http://localhost allowed for local dev).

Self-host

See docs/self-host.md.

License

ISC

About

The easiest way to manage enviornment variables across your devices.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages