Envault

Introduction

Onboard developers to project secrets in seconds with `envault login` and `envault pull`.

Welcome to Envault

Envault is a developer onboarding tool for project secrets. It replaces manual .env sharing with a fast terminal flow: run envault login, run envault pull, and start coding.

For teams using GitHub, Envault's Just-in-Time (JIT) integration checks repository collaborators during envault pull and grants Viewer access automatically when eligible. That means no manual invite loop for every new teammate.

Envault's repository is visible for transparency and security auditing under a proprietary all-rights-reserved license, with MIT-licensed exceptions for mcp-server/ and src/lib/sdk/. Learn more about our licensing.

Why Envault?

Traditional onboarding still means asking someone for a .env file, waiting for access, and troubleshooting setup drift. Envault standardizes onboarding to two commands in the repo (after one-time CLI install and project linkage): envault login -> envault pull.

Quickstart (10 seconds)

envault init
  • envault init: Maps the repository to an Envault project and writes envault.json.
  • During init, select the default environment (for example development).
  • Commit envault.json to GitHub so every teammate gets the same project linkage and default environment context.

Phase 2 (New Teammate): 10-Second Onboarding Flow

envault login
envault pull
  • envault login: Authenticates your local CLI session.
  • envault pull: Uses committed envault.json, then pulls and decrypts project variables into your local .env file.
  • With GitHub JIT enabled: active repository collaborators get Viewer access on pull without a manual invite.

Core Features

Envault isn't just a database for strings. It's a complete ecosystem for secret lifecycle management.

Setup Speed First

Built for terminal-first onboarding and daily developer workflows.

  • Two-Command Onboarding: envault login followed by envault pull.
  • One-Time Project Initialization: envault init links the repo and stores default environment context in committed envault.json.
  • GitHub JIT Access: Repository collaborators receive automatic Viewer access during pull.
  • Unified CLI: A zero-dependency Go CLI for local development flows.
  • Project Workspaces: Isolate secrets by project (e.g., web-app, backend-api).

Security And Access Controls

Security remains built in, but now as the trust layer behind fast onboarding.

  • AES-256-GCM Encryption: Utilizing a robust envelope encryption strategy.
  • Client-Side Decryption Boundary: Secrets are decrypted locally in the CLI, and the server never processes plaintext environment variables.
  • Automatic Key Rotation: Rotate keys seamlessly without downtime.
  • Passkey Support: Passwordless, biometric login powered by WebAuthn.
  • Team Collaboration: Granular permissions (Owner, Editor, Viewer) for every member.
  • Dedicated Support Page: Integrated troubleshooting options directly within the app.
  • Interactive Changelog: Beautiful, animated timeline with comet scroll physics and paginated release history to keep you updated on Envault features.

Performance & Design

  • Modern UI: A stunning, responsive dashboard built with Next.js, Tailwind CSS, and Shadcn UI.
  • Interactive Visuals: Experience 3D elements powered by React Three Fiber.
  • Keyboard Navigation: Move through your secrets as fast as you type.
  • Accessible Haptics: Tactile feedback for high-value interactions on iOS and Android with a built-in user opt-out preference.

How it Works

At a high level, Envault acts as the single source of truth for your environment variables.

  1. Push: Developers push encrypted secrets to a central project.
  2. Authorize: GitHub JIT and RBAC decide who can pull.
  3. Pull: Developers run envault pull to sync secrets locally in seconds.

Tech Stack

Envault is built on the giants of the modern web.

On this page