Never send a .env file again.
ENV syncs your .env files across your team, CI, and deployments, fully encrypted with a key generated on your machine. You hold the key. Hyphen stores ciphertext it can’t read.
Every secret follows the same path. Encrypt local. Push ciphertext. Pull anywhere.
- 01
Initialize once
Run hx init. Your app is registered and a 256-character encryption key is generated on your machine, in a .hxkey file only you hold.
- 02
Keep your .env files
Work the way you already do: default, development, production, and custom environments. .env.local never leaves your machine.
- 03
Push ciphertext
hx push encrypts locally with AES-256 and stores only the result. Every push is a new immutable version you can return to.
- 04
Pull anywhere
Teammates, CI, and Deploy pull with the key and decrypt locally. Every push, pull, and denied request lands in the access log.
Everything a vault does, without trusting the vault.
Versioning, auditing, rotation, and CI wiring, built on encryption not even Hyphen can see through.
Encryption and decryption happen on your machine with a key Hyphen never has. What we store, no one can open, including us.
Every push creates an immutable version. Pull any of them and push it back: you’ve reverted without rewriting history.
Every access is logged with user, IP address, version, and environment, so you can answer audits instead of dreading them.
One command re-encrypts every environment. Old versions still decrypt while the new key rolls out, so you rotate on your schedule, not downtime’s.
The env-action decrypts inside the job container only, as .env files or exported variables. The key never reaches Hyphen.
IP access rules deny any request from an unknown address, even one carrying valid credentials.
Deploy pulls your ENV at container start, per environment, so images stay clean and previews get their own secrets.
You always know who pulled what. And who got denied.
Push, pull, or deny: every request lands in the access log with user, IP address, version, and environment.
One encrypted source of truth. Everywhere your secrets go.
Every environment
Default, development, production, and any custom environment you define, each with its own versions, secrets, and access history.
Read the quickstartEvery workflow
The hx CLI, GitHub Actions, Docker, and Hyphen Deploy all pull from the same encrypted versions, decrypted only where the key lives.
See the CLIEvery requirement
Key rotation, access logs, and IP rules give you the controls standards like PCI-DSS and GDPR expect, without building them yourself.
Ship it with DeployFrequently Asked Questions
How do I securely manage environment variables and secrets across multiple environments?
Hyphen ENV lets you manage secrets across development, staging, production, and custom environments using the familiar .env file format. Secrets are end-to-end encrypted with AES-256-CBC keys generated locally on your machine, so your data is never visible to Hyphen. Config inheritance lets you define values once and override per environment, reducing misconfiguration risk.
What is the best secrets management tool for developers and small engineering teams?
Hyphen ENV is built for developer teams that need enterprise-grade security without the complexity of tools like HashiCorp Vault. It integrates directly with popular cloud providers, CI/CD tools, and developer frameworks to automatically inject secrets during build and deployment. Push and pull secrets with the CLI, manage access by user, environment, and IP address, and get full audit logs without a dedicated DevOps team.
How do I share secrets with my team without exposing them in code or Slack?
ENV provides a secure, auditable way to share secrets across your team. Every team member pulls encrypted secrets directly to their local environment using the Hyphen CLI. Detailed access logs show who accessed what and from where, giving you full visibility. Environment firewalls let you restrict access by IP and subnet for sensitive environments like production.
How do I rotate encryption keys and manage secret versions without downtime?
Hyphen ENV supports no-downtime key rotation, letting you update encryption keys without interrupting your running applications. Full version history is available for every environment, making it simple to view past versions and revert when needed. Safety checks warn you before pushing local changes that conflict with updates made by other team members.
How do I integrate secrets management into my CI/CD pipeline and cloud infrastructure?
ENV integrates with popular cloud providers and CI/CD tools out of the box. Use the Hyphen CLI to pull secrets into your build pipeline, inject them at deploy time, and manage them across environments from the command line. Environment firewalls and precise access controls ensure only authorized services and IP addresses can access production secrets.
Start in one command.
Install the CLI, run hx init, and push. Your team pulls secrets encrypted with a key only you hold.