Skip to main content
Use capy run around local Next.js commands. It gives Next decrypted values through process.env; no application SDK is required.
1

Install the CLI

On macOS, Linux, and Git Bash, the release installer selects a native binary when available:
2

Sync your secrets

The first run authenticates you, creates or selects a Capy project, encrypts values in .env, and creates keep.lock. Commit keep.lock; it contains project metadata and hashes, not plaintext values or keys.
3

Wrap development commands

Your app continues to read values normally:
4

Choose a deployment path

For Vercel, configure a Vercel target with capy deploy. The target writes selected values to Vercel and uses a deploy PR, so Vercel reads its normal environment variables; it does not need capy run in the build.For a platform where you control the process, use the token-and-instructions path from capy deploy, set SECRETS_BLOB and PROJECT_KEY together, and wrap the build or start command with capy run. In deployed mode, capy run writes .capy/next-env.js with variable-name lookups so Next can inline selected values at build time.

Build-time inlining

When using the runtime-pair path with next build, capy run writes .capy/next-env.js with every decrypted variable name. Do not export that whole map through Next’s env option: values in that option can be bundled into client-side code. Select only names that are intentionally public, and guard the import because local runs do not create the file.
The generated file maps names to process.env reads; it does not contain plaintext values. The explicit publicNames list is the security boundary for values Next may inline into browser output. Server-only secrets can still be read from process.env in server-side code, without adding them to env.

Self-hosted Next.js

Use a runtime pair and a wrapped entrypoint:
SECRETS_BLOB and PROJECT_KEY must both be present. With neither pair set, capy run uses the local .env and keep.lock in the working directory.

What’s next

Deploying

Target delivery and runtime-pair setup.

Running your app

Local and deployed runtime behavior.
Last modified on October 2, 2026