Glossary
The words getmyenv uses for the vault, contexts, tokens, machines, guest projects and backups, and what each one means in the product.
Last updated: 2026-09-28
Vault
- Vault password: one per account. It encrypts your private key on your device. We never store it.
- Context key: a random key per context. Values are encrypted with it. It is sealed to each public key that may read the context.
- Lock: the vault state, and the CLI
lockcommand that clears unlocked keys from the OS keychain.
Contexts
- Context: one set of values in a project, such as Development or Production.
- Open: folder tokens can read and write it.
- Read-only: a context protection. The CLI reads it with a server token. Set values in the dashboard.
Tokens
- Folder token: made by browser sign-in in a folder, or on the CLI page. Reads and writes open contexts. Saved in
.getmyenv/token.json. - Server token: made on the CLI page for one Read-only context. For production and CI. Needs an IP allowlist.
- Guest token: made by
guestfor a project without an account.
Trust
- Trusted machine: a machine that reads a Read-only context without asking for approval each time.
- Remember this browser for 30 days: skips the email login code in this browser. MFA still applies.
Guest projects
- Guest project: made without an account. Claim it with
npx getmyenv claimto keep it. - Expired guest project: after 30 days, values can't change.
runstill works. After 60 days it may be deleted.
Backup file
- Backup file: an encrypted
.getmyenv-backupfile of your open contexts. It opens with the Vault password in effect when it was made. Not the.getmyenv/folder.