Working in a project
The variable table#
Opening a project lands on its variables, with tabs for All plus each of the three environments, a debounced server-side search, and a tag-filter row if tags are enabled.
Each row supports edit, delete, reveal, version history with rollback, and — when sharing is enabled — sending a share link. Selected rows can be bulk-deleted from a floating action bar. Deleting warns that the variable is recoverable for 7 days, after which it and its vault value are purged.
The create button reads Add Variable or Request Variable depending on your role. The same drawer has a Bulk Paste tab for a whole .env block.
Rotation, if your plan includes it, is a checkbox in the same form with presets of 30, 60, 90 (default), 180, or 365 days. See Rotation & expiry.
Requests#
A project's requests list links through to the reviewer inbox at /dashboard/requests, tabbed by Pending / Approved / Rejected / Canceled. Only reviewers can act.
Before accepting, a reviewer picks which environments to approve for. A machine-filed request — from an API key over MCP — shows a masked input reading "Enter the value to approve": the reviewer types the secret, and Accept stays disabled until both an environment and a value are supplied. The value is encrypted before the approval runs.
Rejection on this screen is a plain confirm dialog; the free-text reason field lives in the CLI's requests reject --reason.
Files#
Project → Files manages secret files: keystores, SSH keys, certificates, service-account JSON.
- Upload — drag and drop or pick a file, then set display name, destination path, environments, and mode (
0600 — owner read/writeor0400 — owner read-only). - Replace contents — swap the bytes while metadata stays locked, so a rotated keystore keeps its path and grants.
- Permissions — per-file grants, the same model variables use.
- Trash — soft-delete with the same 7-day retention.
Compare environments#
The diff page compares two or more environments (default development vs production), classifying each key as matching, changed, or missing — based on vault references, not decrypted content, until you reveal. If two references differ but the decrypted values are byte-identical, a content match badge says so rather than reporting a false diff.
Search, filter to sensitive-only, sort, reveal individually or all at once, and export as per-environment .env files or a JSON/Markdown report. For a key missing from one environment there is a copy-from helper — there is no one-click sync mutation.
Shared variables#
The same credential often lives in several projects. Sharing keeps one row that every picked project reads, so a rotation is one edit.
Sharing is off until an owner turns it on under Organization → Settings → Shared variables. Turning it off later stops new sharing only; groups that already exist keep working for every client.
A row whose key also exists in other projects shows same key in N projects. Its Share across projects action opens a sheet listing every project you can manage: projects holding the same value are preselected and their copies are moved into the shared row (they land in each project's trash for 7 days); projects with a different value are listed but cannot be picked until that is resolved. Pick an existing group or name a new one and confirm.
Shared rows appear pinned above the table in every project that reads them, with a N projects pill. Edit and delete work in place and state how many projects change before you confirm. You can edit a shared row only if you could edit variables in every project it reaches. If any of those projects protects an environment the row is in, the edit is filed as a change request instead of landing directly.
Stop sharing here removes this project from the group. By default the current values are copied into the project first, so its next pull is unchanged. The last project to leave takes the group with it.
The CLI, the editor extensions, the MCP server, the GitHub Action and the Docker image all receive shared rows with no update: resolution happens on the server. Pushing a shared key from a client is refused with a message naming the group.
Merge in one click. The same settings tab lists every key that is identical across projects, and the dashboard shows the count. Merge all opens a sheet with three environment chips. Development and staging are on by default and merge on the spot. Production is off by default; when it is on, a key that reaches a project protecting production is not merged directly but filed as a change request for a second person to apply, exactly like a production edit. Keys with different values, or with an environment that is off, are held back with the reason and never touched.
Groups are listed and renamed under Organization → Settings → Shared variables. Shared variables are a Pro feature; on the free plan the switch shows "Not available on this plan".
Trash#
Soft-deleted variables and shared accounts are listed separately, each restorable individually. Retention is 7 days, shown per row as "Deleted N days ago — M days left", turning red at one day or less. Empty trash purges everything immediately, destroying the vault values.
Restoring re-runs the uniqueness check — a restore that would collide with a newer variable is rejected, not merged.
Shared accounts#
/accounts holds shared accounts — credential pairs for a shared Stripe login or a database admin account, kept separate from variables. Create with a name, optional URL, username, masked password, description, and environments. Edit, delete, reveal, manage permissions, and share, with the same 7-day trash retention.
Sharing#
The Sharing page manages share links: one-time or time-limited links that reveal a single value to someone outside the project, gated by email verification. It shows totals — active, viewed, expired, revoked — and each card's type, recipient status, and countdown.
The only action here is Revoke. Links are created from the share button on a variable or account row.
Members#
A project's Members page assigns existing organization members to the project. For environment-scoped roles, a checklist restricts which environments they see. Roles themselves are organization-level — see Roles & permissions.
Settings#
Two tabs:
- General — name, description, icon and colour, and VS Code auto-unsync behaviour (Pro).
- Danger Zone — transfer the project to another organization, or delete it. Deletion gives variables and accounts the same 7-day trash retention as a manual delete.
There is no CI/CD Tokens tab. Legacy service tokens still work through a compatibility fallback, but new automation uses an API key from Organization Settings.
Limits#
- Environments are fixed at three. There is no way to add a fourth.
- Variable search returns at most 100 matches at a time.
- Diff compares vault references first — a reveal is what decrypts.
- Trash is 7 days, then permanent.