Skip to content

Glossary

The words getmyenv uses for the vault, contexts, tokens, machines, guest projects and backups, and what each one means in the product.

Last updated: 2026-09-28

Vault

  • Vault password: one per account. It encrypts your private key on your device. We never store it.
  • Context key: a random key per context. Values are encrypted with it. It is sealed to each public key that may read the context.
  • Lock: the vault state, and the CLI lock command that clears unlocked keys from the OS keychain.

Contexts

  • Context: one set of values in a project, such as Development or Production.
  • Open: folder tokens can read and write it.
  • Read-only: a context protection. The CLI reads it with a server token. Set values in the dashboard.

Tokens

  • Folder token: made by browser sign-in in a folder, or on the CLI page. Reads and writes open contexts. Saved in .getmyenv/token.json.
  • Server token: made on the CLI page for one Read-only context. For production and CI. Needs an IP allowlist.
  • Guest token: made by guest for a project without an account.

Trust

  • Trusted machine: a machine that reads a Read-only context without asking for approval each time.
  • Remember this browser for 30 days: skips the email login code in this browser. MFA still applies.

Guest projects

  • Guest project: made without an account. Claim it with npx getmyenv claim to keep it.
  • Expired guest project: after 30 days, values can't change. run still works. After 60 days it may be deleted.

Backup file

  • Backup file: an encrypted .getmyenv-backup file of your open contexts. It opens with the Vault password in effect when it was made. Not the .getmyenv/ folder.
    Glossary · getmyenv