❯envpilot
featurespricing❯docsblogchangelogwishlistfaq
sign-inget-started
// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
Start HerePlatformPlans & LimitsCLIVS CodeGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
❯envpilot

Encrypted environment variables for teams that live in the terminal. No .env files, no secrets in Slack.

$npm install -g @envpilot/cli

// product

  • Features
  • Pricing
  • Changelog
  • Wishlist

// resources

  • Getting Started
  • CLI Reference
  • VS Code Extension
  • Security

// compare

  • vs Doppler
  • vs Infisical
  • vs .env files

// support

  • FAQ
  • Support
  • Contact
  • Docs
  • Status

// legal

  • Privacy Policy
  • Terms of Service

© 2026 Envpilot · Built at Syntax Lab Technology · Abdul Rafay

ENVPILOT

❯envpilot
featurespricing❯docsblogchangelogwishlistfaq
sign-inget-started
// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
Start HerePlatformPlans & LimitsCLIVS CodeGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
❯envpilot

Encrypted environment variables for teams that live in the terminal. No .env files, no secrets in Slack.

$npm install -g @envpilot/cli

// product

  • Features
  • Pricing
  • Changelog
  • Wishlist

// resources

  • Getting Started
  • CLI Reference
  • VS Code Extension
  • Security

// compare

  • vs Doppler
  • vs Infisical
  • vs .env files

// support

  • FAQ
  • Support
  • Contact
  • Docs
  • Status

// legal

  • Privacy Policy
  • Terms of Service

© 2026 Envpilot · Built at Syntax Lab Technology · Abdul Rafay

ENVPILOT

// documentation
Start Here
  • Quickstart
  • Core concepts
  • Architecture: the machine surfaces
Platform
  • Data model
  • Variables
  • Secret files
  • Shared Accounts
  • Secret Sharing Links
  • Diagrams in documentation
  • Sharing documentation
  • Roles & permissions
  • Requests & approvals
  • Rotation & expiry
  • Security
Plans & Limits
  • Plans & Limits
  • Rate limits
CLI
  • CLI overview
  • Authentication & accounts
  • Linking projects
  • Pull & push
  • Running commands with secrets
  • Single secrets
  • Requests
  • Secret files
  • Command reference
  • CLI in CI & troubleshooting
VS Code
  • VS Code overview
  • Linking & sync
  • Protection
  • Editor features
  • Commands
  • Settings
  • Troubleshooting
GitHub Action
  • GitHub Action overview
  • Inputs & outputs
  • Secret files in CI
  • Recipes
  • Action security
Docker
  • Docker overview
  • Build time
  • Runtime
  • Docker Compose
  • Docker reference
API Reference
  • API overview
  • API Quickstart
  • Authentication
  • Errors
  • Organization
  • Projects
  • Variables
  • Shared accounts
  • Secret files
MCP Server
  • MCP overview
  • MCP setup
  • Connecting a client
  • Tools
  • Agent requests
Web Dashboard
  • Dashboard overview
  • Working in a project
  • Organization administration
Integrations
  • Slack & Discord Notifications
Guides
  • How to Share Environment Variables Securely
  • Next.js Environment Variables Best Practices
  • Android keystore in CI
  • Giving an agent secrets safely

// resources

  • github
  • npm
  • vs code marketplace
Start HerePlatformPlans & LimitsCLIVS CodeGitHub ActionDockerAPI ReferenceMCP ServerWeb DashboardIntegrationsGuides
QuickstartCore conceptsArchitecture: the machine surfaces
docs/Start Here

Core concepts

Organizations, projects, environments, variables, secret files, roles, and requests — the whole object model on one page.

open in claudeopen in chatgptopen in cursor

Core concepts

Six objects, and one rule about how they combine. Everything else in these docs is a surface over this model.

Organization#

The top-level container for your team: a name, a URL slug, members, billing, and API keys. If you are the first person on your team to sign up, you create one before anything else exists. A user can belong to several organizations; the free plan allows one organization per owner.

Project#

A project lives inside an organization and holds variables and secret files — typically one project per app or service (api, web, worker-jobs). Projects have their own name, slug, optional description, and project-level role assignments.

Environment#

Every project has exactly three environments: development, staging, production. There is no fourth, and custom environments cannot be added — the three-environment model is fixed across the dashboard, CLI, extension, GitHub Action, REST API and MCP server.

Every variable and every secret file is scoped to one or more of them.

Variable#

A key, a value, a set of environments, an optional description, tags, and a "sensitive" flag.

The uniqueness rule

The same key may exist on several active variables in a project as long as their environment sets do not overlap. DATABASE_URL for [development] and DATABASE_URL for [production] are two independent variables with independent values. Overlapping environments for one key are rejected, naming the clash.

That invariant — every (key, environment) pair resolves to at most one active variable — is what makes envpilot pull, extension sync, and the public API deterministic. It is enforced on every write path, including request approvals and restores from trash. See Variables.

Sensitive is a display flag, not an encryption flag#

Marking a variable sensitive masks it (••••••••) in the dashboard until someone reveals it. That is all it does.

Every value, sensitive or not, is encrypted at rest in WorkOS Vault; Convex stores only a vault reference id, never plaintext. "Sensitive" controls who casually reads a value over your shoulder, not how it is stored. See Security.

Secret file#

Some secrets are not text you can paste into a .env: an Android signing keystore, an SSH private key, a .p12 certificate, a service-account JSON. Those are secret files — binary blobs with a recorded destination path and POSIX mode, so a fresh clone can materialise everything a build needs.

They are stored differently from variables (envelope encryption: ciphertext in Convex storage, key in Vault) and carry their own limits. See Secret files.

Role#

Every member holds one organization role, plus optional per-project roles and per-variable or per-file grants. Roles decide two things: what you can read, and whether your write lands immediately or becomes a request for someone else to approve. See Roles & permissions.

Request#

A request is an ask, not a write: "I need STRIPE_SECRET_KEY in production, here is why." Developers file them, reviewers approve them and supply the value. Coding agents can file them too over the MCP server — which is the only mutation any machine credential is allowed to perform. See Requests & approvals.

How the pieces map to surfaces#

You want to…Use
Manage everything, invite peopleDashboard
Work in a terminal, script CICLI
Stay in the editorVS Code extension
Pull secrets in a workflow runGitHub Action
Read from your own programREST API
Give a coding agent scoped accessMCP server

Next#

  • Architecture — one enforcement core behind all six surfaces
  • Plans & limits — what each tier allows

Limits worth knowing early#

  • Three environments, fixed. No custom environments on any plan.
  • One role per member, organization-wide; project assignments narrow where it applies.
  • Free tier: 3 projects, 50 variables per project, 3 members, 3 secret files, 1 organization.
  • Deleted variables, accounts and files are recoverable for 7 days, then purged permanently.
← start hereQuickstart
start here →Architecture: the machine surfaces

// on this page

  • Organization
  • Project
  • Environment
  • Variable
  • Sensitive is a display flag, not an encryption flag
  • Secret file
  • Role
  • Request
  • How the pieces map to surfaces
  • Next
  • Limits worth knowing early