Skip to content

Changelog

Notable changes to getmyenv. CLI versions match the getmyenv npm package.

0.8.0

Published with @getmyenv/shared 0.5.0 and @getmyenv/crypto 0.4.0. CLIs older than 0.8.0 are asked to update. The database starts fresh. Data from earlier versions does not carry over.

Key model

  • Each account has a key pair. The private key is encrypted with your Vault password. One Vault password per account.
  • Each context has its own key, sealed to the public key of each holder: you, members you share it with, and server tokens for that context.
  • Server tokens hold the key of their one context. Production and CI machines never need the Vault password.
  • Copy between contexts, rename and restore decrypt and encrypt again in the browser or CLI.
  • Backups use a new format with the .getmyenv-backup extension. Backups from earlier versions cannot be restored.

Sharing, templates, known keys

  • Share a project: invite by email, with read or write per context. Your browser seals the context keys to the member after you check their key fingerprint. Removing a member rotates the keys by default. Transfer a project to a member.
  • Only projects you own count toward the open pilot limit.
  • Templates: a link that lists the variable names an app needs. Names only, never values. Fill values in the dashboard, or run npx getmyenv start --template <id>.
  • Add variable suggests names that SDKs read, with a link to get each key. set and import print "Did you mean" for near misses.

CLI

  • start runs setup, like bare npx getmyenv. Setup with no .env prints the next step.
  • The Vault password needs 12 characters or more, with a letter and a number, as in the dashboard.
  • claim.json is gitignored. The guest passphrase is printed once, at creation. Claim shows a code in the terminal and on the claim page. They must match.
  • A token.json tracked by git is refused.
  • export -o and backup -o refuse symlinks and never overwrite a file.
  • lock clears every keychain entry.
  • Fixed: after the first question, setup ignored what you typed. The project name prompt in start waited forever.

Web

  • Sign in with Google. MFA still applies when enabled.
  • Google sign-in links to an existing account with the same email when Google hosts that mailbox (Gmail or Google Workspace). Other emails: sign in with email, then connect Google in Settings.
  • Settings: connect or unlink Google next to GitHub.
  • Admin: the GitHub logins chart is now OAuth logins (GitHub and Google).
  • Dashboard: a project and context sidebar. Each context opens as its own page with a variables table.
  • Dashboard: reveal a value inline. It hides after 20 seconds. Copy the run command for a context.
  • Remove a variable: clear its value in one context, or delete it from every context.
  • Filter the variables table by name and by tags. Selected tags stay in the URL (?tag=) across contexts.
  • Import shows the values it will replace before saving.
  • Confirm dialogs before revoking or untrusting a machine, revoking a token, and rotating a webhook secret.
  • Pages show an error with a retry button when loading fails.
  • Settings: a Security tab with Vault password change and two-factor authentication.
  • Toasts are solid and stay above dialogs. Clicking a toast no longer closes the dialog under it.
  • A 404 page that returns to the homepage, or to your projects when signed in.
  • Saving on the variables page updates the table in place instead of reloading the whole page.
  • Renaming the current context's slug keeps you on that context.
  • Add variable refuses a name that already exists.
  • Tags: check one or more in the menu above the table, with Select all and Unselect all. Click a tag in the table to show only that tag, click again to clear.
  • Phones: a bottom tab bar with Projects, Activity, Requests, Settings and More. Add variable is a floating button on a context page. Variable and context dialogs fill the screen.
  • Context page: the title opens a menu to switch context or project, add a context, and open context settings. Read-only contexts show a server icon. An empty context shows its run command and Import.
  • Context settings is a page at /projects/{id}/{context}/settings: run command, name, slug, protection, import, export, and delete.
  • New icons: a folder for each project, code for Open contexts, a server for Read-only (the same icon as server tokens on /cli). The Read-only label no longer wraps on narrow screens.
  • The footer no longer links llms.txt and llms-full.txt. They stay at the site root, in the sitemap, on /docs, and as alternate links in the page head of the homepage and /docs.
  • Every control shows the same focus ring when you move with the keyboard. Rings have room around them and are not cut off.
  • Dialog titles align left on phones. Projects: Rename and Delete are icons pinned to the right edge of the table.
  • Context settings: Delete context has its own section and a confirm step.
  • Editing a value while the vault is locked: tap the value field to unlock.
  • Dialog buttons stay pinned to the bottom while the content scrolls. They sit side by side, also on phones, and wrap instead of scrolling sideways.
  • Import: copy values from another context, filling empty values or also replacing existing ones. Add variable, Import and Export act on the context you are viewing.
  • Rename a variable from its edit dialog. The new name applies in every context.
  • Variable dialog: shorter header. Field help sits behind an info icon.
  • Variables: click a row to set or edit it. A missing chip filters to values not set yet. Add variable can set an expiry.
  • New context dialog is shorter. On small screens the title keeps the project name and shortens the context name.
  • Project pages live at /projects/{id}/{context}. Projects in the nav opens the last project you used.
  • Set Vault password and Unlock vault fill the screen on phones. Expires is the last field in variable dialogs. Name and Tag explain that they apply in every context.
  • Clearer variable copy: one word for missing values, plain delete and expiry help, and remove buttons that match their text.
  • Dashboard API: variable routes live under /api/projects/{id} (grid, keys, contexts/{id}/values, contexts/{id}/ciphertext). The CLI is unchanged.
  • New device sign-in email shows the browser and OS, IP, and country instead of the full user agent.
  • Practical guides at getmyenv.com/guides.
  • Landing: numbered steps, and who uses it (human, teammate, machine, AI agent).
  • Sign-in: check Remember this browser for 30 days to skip the email code, with email, GitHub or Google. Sign out forgets the browser.
  • Admin: delete all guest projects past expiry and grace in one step. Nothing deletes them on a schedule.
  • Vault dialog on phones: the icon, title and password field sit centered, with Cancel and Unlock at the bottom.
  • The vault button shows the state, Locked or Unlocked. Click it to unlock or lock. Before a vault exists it says Set password.
  • Locked contexts are now labeled Read-only in the dashboard, docs and CLI output. The stored value, the API and CLI flags stay locked.
  • Docs: a Glossary page, and "What each file or leak exposes" on the Security page.
  • llms.txt and llms-full.txt are generated from the docs and guides.
  • A public changelog at getmyenv.com/changelog.
  • Database migrations start from one initial migration.

Security

  • Client IP comes from one header set by your proxy (TRUSTED_IP_HEADER). Server-token IP allowlists apply on every CLI route.
  • Writes are refused while an admin views as a user.
  • The vault key cannot be replaced while values exist.
  • Login code attempts are limited with one atomic update.
  • SESSION_SECRET feeds HKDF-SHA256 with one key per purpose. Existing TOTP seeds, pending login codes and webhook signing secrets stop working. Two-factor turns off on its own, so set it up again. Rotate webhook secrets.
  • Webhooks check the resolved IP when the socket connects and refuse private and reserved addresses, including IPv4 inside IPv6. Retries run after 1 minute, 5 minutes, 30 minutes and 2 hours, are stored, and continue after a restart.
  • Account deletion also deletes that account's activity history.
  • CLI sign-in shows a code in the terminal and on the approval page, and only the CLI that started the sign-in can collect the token.
  • Sign-in redirects accept same-site paths only.
  • Rate limits count in one database statement, so parallel requests cannot pass the limit.
  • Two-factor codes are rate limited. An unreadable two-factor seed turns two-factor off instead of blocking sign-in.
  • Admin project deletes are recorded as security events. Deleting a project sends project.deleted to its webhooks first.
  • GitHub sign-in checks every GitHub response and uses a verified email only.
  • A Vault password change, account delete, removing a member and transfer need a sign-in code from the last 5 minutes.
  • Authenticator codes cannot be reused. Sessions have an idle timeout. Signing in ends the previous session. Changing MFA or unlinking a sign-in method ends other sessions. Session cookies use the __Host- prefix.
  • Email sign-up creates the account after the code is verified.
  • The content security policy applies to every page.
  • Rate limits on OAuth callbacks, browser sign-in, webhook tests and access-request emails.
  • Staff accounts must enrol in MFA before anything else.
  • While an admin views as a user, key material is never returned.

Removed

  • Old URL redirects (/dashboard, /secrets, /backups/new, old docs slugs). Unknown pages show the 404 page.
  • Backups from earlier versions are no longer read.
  • CLIs older than 0.8.0. They are asked to update.
  • --vault-password-stdin. Server tokens hold their context key.
  • The project.created webhook event. No webhook exists before its project.
  • Zip backup import, the old /webhooks page, the admin two-factor disable route, webhook test, retry and rotate actions on the update route, and unused exports in the shared and crypto packages.

0.7.0

Published with @getmyenv/shared 0.4.0 and @getmyenv/crypto 0.3.0. Older CLIs keep working with the new server.

Web

  • Server tokens have a New machines rule next to their IP allowlist on /cli: Ask me (default), Trust from these IPs, or Blocked. Edit it with Edit access, without revoking the token.
  • Trust from these IPs trusts a machine on its first read from an allowed IP and emails you. Every allowlist entry must be /24 or narrower (IPv6 /64). If the allowlist gets wider, the token asks again.
  • Requests: the machines table is called Machines. Each machine shows Trusted or Not trusted, and machines that are not trusted have a Trust button.

CLI

  • run says when a machine was trusted on its first read.
  • status shows the New machines rule of a server token.

Removed

  • The Access requests On/Off column on /projects and the accessRequestsEnabled project field. Server tokens of projects that had it off now use Blocked.

0.6.2

Published with @getmyenv/shared 0.3.0 and @getmyenv/crypto 0.3.0.

CLI

  • Output says read-only instead of locked for read-only contexts.

Removed

  • The CLI no longer reads older token.json and project.json formats. Run getmyenv start again in that folder.

0.6.1

Same CLI code as the published 0.6.0. These CLI changes shipped in 0.6.0 and are listed here.

CLI

  • lock forgets the unlocked project key on this machine.
  • Open contexts: after you enter the Vault password in a terminal, the unlocked project key stays in the OS keychain for 8 hours. Locked contexts, CI and --vault-password-stdin still ask each run. Guest projects unlock with claim.json. GETMYENV_KEYCHAIN=0 turns it off.
  • Prompts go to stderr. The update check no longer blocks.
  • .env parsing matches dotenv.
  • run passes signals and exit codes through.
  • --yes and --dry-run on import and restore. set KEY --stdin reads a value from stdin.
  • Commands work from subfolders of a linked project.
  • --api-url works before or after the command name. help [command] is a command.
  • export adds the file to .gitignore and makes it owner-only on macOS and Linux.
  • import exits with an error when every file was skipped.
  • unlink keeps token.json when the server cannot revoke the token.
  • Pasting the Vault password works. The keychain is read even when stdin is piped.
  • GETMYENV_MACHINE_LABEL names the machine in access requests.
  • Output says "variable" instead of "key".

Removed

  • The CLI no longer cleans up files from versions before 0.6.0 (credentials.json, wrapped-key.json, a whole-folder .getmyenv/ ignore line).
  • Old command names (push, pull, remove, delete, whoami) now fail as unknown commands. The build clears old files from dist.

0.6.0

Contexts replace environments and secrets. A project has variable names and a set of contexts. Each context holds one encrypted value per name.

Added

  • Contexts with free names and generated slugs. New projects start with Development (open) and Production (locked).
  • Open and Locked protection. Locked contexts are read-only in the CLI and need a server token.
  • Server tokens: bound to one locked context, read-only, with an IP or CIDR allowlist.
  • Machine access: a new machine asks for approval before it reads a locked context. Approval gives a one-time grant for 1 hour. Trust a machine to skip approval.
  • run [context], --explain, --keep-existing, --allow-missing.
  • context list, context create --from, context use.
  • status, ls, set, unset, import, export.
  • guest and claim for projects started without an account.
  • Value expiry. After the date, getmyenv stops providing the value.

Changed

  • push is now import or set.
  • pull is now export.
  • remove is now unset.
  • delete is now unlink.
  • whoami is now getmyenv with no command.
  • CLI versions older than 0.6.0 are asked to update.