capy
Git-style end-to-end encrypted secrets CLI
TLDR
SYNOPSIS
capy [subcommand] [options] [args]
DESCRIPTION
capy is a secrets toolchain with git-style primitives — sync, branch, deploy, invite, and kick — that encrypts values on your machine before they leave. The service stores membership records and ciphertext only; decryption needs a key share that never leaves the client. Your `.env` becomes versioned state the team can commit (`keep.lock`), roll back, and offboard without rotating every application key.On first run in a project with a plain `.env`, Capy encrypts each value in place to `capy:{resourceId}:{ciphertext}` snippets and backs up the original as `.env.pre-capy.old`. capy run decrypts into process memory and spawns any command that reads environment variables. capy kick makes the removed user's local key cryptographically inert without rotating the master key for remaining members.Branches parallel git: each Capy branch holds its own secret state and access list; git branches pin to a Capy branch via committed `keep.lock`. Offline capy run works from the local cache after the first authenticated sync.
PARAMETERS
(no subcommand)
Three-way sync between local `.env`, pinned `keep.lock`, and remote. Initializes the project on first use.run -- command...
Decrypt secrets in memory and run command with them as environment variables.edit
Interactive table of variables: reveal, edit, drift/conflict status.status
Show drift between local, pinned, and remote.push
Push local changes without pulling.lock
Lock the local key so the passphrase is required next time.deploy
Generate a deploy token and walk through platform setup (Vercel, Cloudflare, Docker, Fly, Railway, Render, Heroku, GitHub Actions, AWS Lambda, and others).connect provider
Pull a credential from a linked provider into `.env`.rotate [var]
Rotate a managed credential.invite email
Invite a teammate (code travels out-of-band).redeem code
Redeem an invite code.kick email
Remove a teammate with cryptographic revocation.users
Interactive member management.org
List or switch organizations.branch, checkout branch
List/switch Capy branches; checkout -b creates.grant-branch, revoke-branch
Protected-branch access control.recover, end-recover
Restore access from a recovery phrase / end recovery.decrypt
Offline decrypt (owner only).use profile, profile
Switch or manage CLI profiles.byoc [url]
Connect to a self-hosted Capy instance when available.info, logout, cleanup, transport
Session info, clear session, remove hooks/local state, move account to another machine.
CONFIGURATION
.env
Project secrets file; values become `capy:...` ciphertext snippets after init.keep.lock
Committed manifest pinning the branch and encrypted resource state (like a lockfile).~/.capy/
Local cache and keys so capy run works offline after the first sync..env.pre-capy.old
Automatic backup of the original plaintext `.env` on first migration (gitignored).
CAVEATS
The hosted service component is not fully self-hostable for all deployments; losing the org owner seed phrase with no other device holding `key.enc` means permanent loss of access by design. First sync needs network; offline work uses the local cache only. CLI is AGPL-3.0; review license obligations for your team.
HISTORY
Capy (npm package @capysc/cli) is an AGPL-3.0 secrets product from Incentv Technologies / capysc, positioned as zero-trust, encrypt-at-source secrets management for humans and agents alongside git.
