❯envpilot
featurespricing❯docsblogchangelogwishlistfaq
sign-inget-started
// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Protected environments
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
JetBrains
  • JetBrains overview
  • Linking & sync
  • Protection
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
  • jetbrains marketplace
Start HerePlatformPlans & LimitsCLIVS CodeJetBrainsGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
❯envpilot

Encrypted environment variables for teams that live in the terminal. No .env files, no secrets in Slack.

$npm install -g @envpilot/cli

// product

  • Features
  • Pricing
  • Changelog
  • Wishlist

// resources

  • Getting Started
  • CLI Reference
  • VS Code Extension
  • Security

// compare

  • vs Doppler
  • vs Infisical
  • vs .env files

// support

  • FAQ
  • Support
  • Contact
  • Docs
  • Status

// legal

  • Privacy Policy
  • Terms of Service

© 2026 Envpilot · Built at Syntax Lab Technology · Abdul Rafay

ENVPILOT

❯envpilot
featurespricing❯docsblogchangelogwishlistfaq
sign-inget-started
// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Protected environments
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
JetBrains
  • JetBrains overview
  • Linking & sync
  • Protection
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
  • jetbrains marketplace
Start HerePlatformPlans & LimitsCLIVS CodeJetBrainsGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
❯envpilot

Encrypted environment variables for teams that live in the terminal. No .env files, no secrets in Slack.

$npm install -g @envpilot/cli

// product

  • Features
  • Pricing
  • Changelog
  • Wishlist

// resources

  • Getting Started
  • CLI Reference
  • VS Code Extension
  • Security

// compare

  • vs Doppler
  • vs Infisical
  • vs .env files

// support

  • FAQ
  • Support
  • Contact
  • Docs
  • Status

// legal

  • Privacy Policy
  • Terms of Service

© 2026 Envpilot · Built at Syntax Lab Technology · Abdul Rafay

ENVPILOT

// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Protected environments
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
JetBrains
  • JetBrains overview
  • Linking & sync
  • Protection
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
  • jetbrains marketplace
Start HerePlatformPlans & LimitsCLIVS CodeJetBrainsGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
Data modelVariablesSecret filesShared AccountsSecret Sharing LinksDiagrams in documentationSharing documentationRoles & permissionsRequests & approvalsProtected environmentsRotation & expirySecurity
docs/Platform

Protected environments

Every write into a protected environment becomes a change request that a second person applies. Covers variables, shared accounts, and secret files across the dashboard, CLI, MCP, and IDE plugins.

open in claudeopen in chatgptopen in cursor

Protected environments

Mark an environment as protected and nobody writes to it directly. Not the owner, not a lead, not an agent. A write becomes a change request: the new secret is encrypted at once, the request waits in the inbox, and a second person applies it. Production stays exactly as it was until then.

Protection is enforced in one place, the backend mutations that write variables, accounts, and files. Every client calls those same mutations, so a new client cannot route around it.

Turning it on#

Project Settings, Protection. Pick the environments to protect. Needs the project.protection.manage capability (owner, project manager, team lead by default) and the Pro plan.

Turning it off never needs the plan. An organization that lost the feature can always remove protection on purpose. Doing so is audited as critical and sent to your security notification channel.

Who does what#

RoleSeesWrites dev and stagingWrites productionProposes a production changeApprovesConfiguresOverride
Ownerallyesvia approvalyesyes, never ownyesyes, audited as critical
Project managerallyesvia approvalyesyes, never ownyesno
Team leadallyesvia approvalyesyes, never ownyesno
Editordev and stagingyesnever, cannot seenononono
Developerdevyesnever, cannot seenononono
Viewerallnononononono

Three rules hold this together.

  1. Nobody writes directly into a protected environment. The only live-write path is override, and every use is audited as critical.
  2. The person who proposed a change never approves it. Two people, always.
  3. Proposing needs no new permission. If you could edit the resource before protection, you can propose the edit after.

Role environment defaults#

Each role carries a default environment scope. Developers get development. Editors get development and staging. Leads, owners, and viewers see everything. Admins change these per role in the admin panel, and a project member's scope can narrow the role default but never widen it.

Out-of-scope resources are hidden, not refused. A developer never sees a production variable, so there is nothing to click. The refusal only appears when someone reaches for it blind, for example envpilot push --env production.

A variable that spans environments holds one value for all of them. If DATABASE_URL is one row covering development and production, a development-only developer cannot be shown it without leaking the production value, so it is hidden entirely. Keep one row per environment for secrets. The variable drawer warns when a new variable spans a scoped and an unscoped environment.

The flow#

  1. A lead edits DATABASE_URL in production and saves.
  2. The backend checks the normal write capability and environment scope, then sees production is protected. It encrypts the new value into the vault, stores a pending change request, and returns "sent for approval". Production is untouched.
  3. Approvers get an email and, if configured, a Slack or Discord message. After 48 hours idle, one reminder goes out.
  4. A second lead opens the request, sees the current and proposed metadata (never plaintext), and approves with a reason. The backend re-checks that the approver is not the requester, that the resource did not change since the request was filed, and that no key conflict appeared, then applies the write in the same transaction.
  5. On reject, cancel, or expiry (30 days idle), the staged secret is deleted from the vault.

What counts as a protected write#

Any write that touches a protected environment, before or after the change: create, update, delete, restore from trash, rollback to an older version, and adding or removing a protected environment from a resource's list. Reads, exports, tags, share links, and rotation reminders are unaffected.

Every client#

SurfaceProtected write
DashboardSave becomes "Propose change". The request appears in the Requests page.
CLI pushRefuses and lists the protected environments. envpilot push --request files one change request per changed key.
CLI secrets set, files addOffers to file a change request.
MCP, VS Code, JetBrainsAlready request-only. Unchanged.
GitHub Action, REST APIRead-only. Unchanged.

Activity log#

Every step writes an audit row: protection.enabled, protection.disabled, change.requested, change.applied, change.rejected, change.canceled, change.expired, change.overridden, change.reminder_sent. Each carries the environments it touched, so searching the audit log for "production" finds them.

← platformRequests & approvals
platform →Rotation & expiry

// on this page

  • Turning it on
  • Who does what
  • Role environment defaults
  • The flow
  • What counts as a protected write
  • Every client
  • Activity log