Skip to content

When getmyenv fits

When getmyenv fits, when one .env file is enough, and how it sits next to .env files, encrypted repo files, secrets platforms and password managers.

Last updated: 2026-10-05

Good fit

  • You work on several projects and keep losing track of their .env files.
  • Teammates need some contexts and not others.
  • An AI editor scaffolds apps and needs values to run them.
  • You deploy to your own servers or CI and want Production read with a server token.
  • You have a few environments and want the same names in each.
  • You want no SDK. Your app keeps reading environment variables.

Not a fit

  • One .env file on one machine, with no teammates. That may be enough.
  • You need values kept in sync with a cloud secret store. push copies a context to Vercel or Netlify once, when you run it. Nothing syncs on its own.
  • You need credentials generated or rotated for you. getmyenv stores the values you set.
  • You need a compliance standard. getmyenv does not claim one.
  • Your app must start with no connection to getmyenv. run fetches the values from getmyenv each time it starts. If it can't reach the server, the command does not start. A running process keeps its values.

Not an encrypted .env in the cloud

A variable has a value per context, not a file per environment. One Vault password per account unlocks your private key on your device. Each context has its own key, and each reader gets their own sealed copy. A key copy lets a reader decrypt. What they can change comes from their share. Only the owner sets Read-only values, in the dashboard.

run checks that every name has a value before it starts your command, and names what is missing.

Next to other tools

  • .env files: plaintext on disk, shared by hand. getmyenv imports them, and run gives the values to the process. run does not read .env files. Delete them when you are ready.
  • Encrypted files in the repo (like SOPS): you keep the file and its keys. getmyenv keeps no values in the repo. .getmyenv/template.json lists names only.
  • Hosted secrets platforms (like Doppler or Infisical): if you use one and it works, keep it. getmyenv is smaller: environment variables, contexts, a CLI and a dashboard.
  • Password managers (like 1Password): getmyenv reads the parent environment, so you can chain them.
op run -- npx getmyenv run staging -- npm start

Next step