Hyphen ENV

Never send a .env file again.

ENV syncs your .env files across your team, CI, and deployments, fully encrypted with a key generated on your machine. You hold the key. Hyphen stores ciphertext it can’t read.

AES-256 · zero-knowledge · versioned · audited
acme — hx — zsh
How it works

Every secret follows the same path. Encrypt local. Push ciphertext. Pull anywhere.

  1. 01

    Initialize once

    Run hx init. Your app is registered and a 256-character encryption key is generated on your machine, in a .hxkey file only you hold.

  2. 02

    Keep your .env files

    Work the way you already do: default, development, production, and custom environments. .env.local never leaves your machine.

  3. 03

    Push ciphertext

    hx push encrypts locally with AES-256 and stores only the result. Every push is a new immutable version you can return to.

  4. 04

    Pull anywhere

    Teammates, CI, and Deploy pull with the key and decrypt locally. Every push, pull, and denied request lands in the access log.

Capabilities

Everything a vault does, without trusting the vault.

Versioning, auditing, rotation, and CI wiring, built on encryption not even Hyphen can see through.

  • Encryption and decryption happen on your machine with a key Hyphen never has. What we store, no one can open, including us.

  • Every push creates an immutable version. Pull any of them and push it back: you’ve reverted without rewriting history.

  • Every access is logged with user, IP address, version, and environment, so you can answer audits instead of dreading them.

  • One command re-encrypts every environment. Old versions still decrypt while the new key rolls out, so you rotate on your schedule, not downtime’s.

  • The env-action decrypts inside the job container only, as .env files or exported variables. The key never reaches Hyphen.

  • IP access rules deny any request from an unknown address, even one carrying valid credentials.

  • Deploy pulls your ENV at container start, per environment, so images stay clean and previews get their own secrets.

Environment: production
storefront · v12 · 201 bytes
DATABASE_URL
STRIPE_SECRET_KEY
REDIS_URL
Hyphen stores ciphertext only. There is nothing to display.
Every access, on the record

You always know who pulled what. And who got denied.

Push, pull, or deny: every request lands in the access log with user, IP address, version, and environment.

Access log
storefront · all environments
live
ActionEnvironmentVersionActorIP address
Coverage

One encrypted source of truth. Everywhere your secrets go.

Every environment

Default, development, production, and any custom environment you define, each with its own versions, secrets, and access history.

Read the quickstart

Every workflow

The hx CLI, GitHub Actions, Docker, and Hyphen Deploy all pull from the same encrypted versions, decrypted only where the key lives.

See the CLI

Every requirement

Key rotation, access logs, and IP rules give you the controls standards like PCI-DSS and GDPR expect, without building them yourself.

Ship it with Deploy

Frequently Asked Questions

How do I securely manage environment variables and secrets across multiple environments?

Hyphen ENV lets you manage secrets across development, staging, production, and custom environments using the familiar .env file format. Secrets are end-to-end encrypted with AES-256-CBC keys generated locally on your machine, so your data is never visible to Hyphen. Config inheritance lets you define values once and override per environment, reducing misconfiguration risk.

What is the best secrets management tool for developers and small engineering teams?

Hyphen ENV is built for developer teams that need enterprise-grade security without the complexity of tools like HashiCorp Vault. It integrates directly with popular cloud providers, CI/CD tools, and developer frameworks to automatically inject secrets during build and deployment. Push and pull secrets with the CLI, manage access by user, environment, and IP address, and get full audit logs without a dedicated DevOps team.

How do I share secrets with my team without exposing them in code or Slack?

ENV provides a secure, auditable way to share secrets across your team. Every team member pulls encrypted secrets directly to their local environment using the Hyphen CLI. Detailed access logs show who accessed what and from where, giving you full visibility. Environment firewalls let you restrict access by IP and subnet for sensitive environments like production.

How do I rotate encryption keys and manage secret versions without downtime?

Hyphen ENV supports no-downtime key rotation, letting you update encryption keys without interrupting your running applications. Full version history is available for every environment, making it simple to view past versions and revert when needed. Safety checks warn you before pushing local changes that conflict with updates made by other team members.

How do I integrate secrets management into my CI/CD pipeline and cloud infrastructure?

ENV integrates with popular cloud providers and CI/CD tools out of the box. Use the Hyphen CLI to pull secrets into your build pipeline, inject them at deploy time, and manage them across environments from the command line. Environment firewalls and precise access controls ensure only authorized services and IP addresses can access production secrets.

Start in one command.

Install the CLI, run hx init, and push. Your team pulls secrets encrypted with a key only you hold.