Sharing and transfer
Share a getmyenv project with access per context. Each member gets their own copy of the context key. Transfer the project when you are done.
Last updated: 2026-09-28
How sharing works
A project has one owner. The owner invites members by email and picks, for each context, whether they can read it or also change values.
Each member gets their own copy of the context key, sealed to their public key. The owner's browser does the sealing. We store sealed keys only.
Invite a member
- Open the project, then Members. Enter an email and tick the contexts.
- The invite link works once, only for that email, and expires in 7 days.
- The member signs in with that email and accepts. If they have no Vault password yet, they set one.
- Back on Members, unlock the vault and click Send keys. Check that the fingerprint matches the one in the member's Settings, then confirm.
Until keys arrive, the member sees variable names but no values.
What members can do
- Read the contexts shared with them.
- Set and clear values in contexts where they can change values.
- Use the CLI in their own folder:
npx getmyenv start, pick the shared project, thenrun,exportandset. - Leave the project from Members.
Only the owner adds contexts, renames or deletes variables, sets tags, manages members, webhooks, backups and server tokens, and deletes the project. Production CLI is read-only for everyone.
Remove a member and rotate keys
Removing a member deletes their copies of the keys, their membership, and their CLI sign-ins for the project.
Rotate keys is on by default. Your browser makes a new key for each context they had, re-encrypts every value in it, and seals the new key to everyone who still has access. Their old copy stops working. The same option shows when you take a context away from a member.
Transfer ownership
Pick a member on the Members page. Your browser first gives them every context with write access and sends any keys they are missing. Then they become the owner.
You choose to stay as a member with write access, or leave. Server tokens move to the new owner. Pending invites are cancelled. We ask for a code first.
Activity and webhooks
Invites, joins, keys sent, removals, key rotations and transfers show in the owner's Activity and can go to webhooks: member.invited, member.joined, member.keys_sent, member.removed, context.key_rotated, project.transferred. Names and emails only. Never values or keys.