> ## Documentation Index
> Fetch the complete documentation index at: https://capy.sc/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Adding secrets

> Add secrets to your active Capy branch from a terminal, browser, or piped input.

Run `capy` in the project first to finish setup. Then check the active secret branch with `capy branch`. The commands below add values to that branch.

## Add from your terminal

Pass variable names, not their values:

```bash theme={null}
capy add API_KEY
# Or add several values in one step:
capy add API_KEY DATABASE_URL
```

Enter each value when prompted. Capy encrypts the values, writes them to `.env`, and syncs them to Capy by default. You do not need a separate `capy push` after a successful addition.

## Add in your browser

To enter the values in a local browser page instead:

```bash theme={null}
capy add API_KEY DATABASE_URL --web
```

Complete the browser form and leave the CLI running until it finishes. Use `--no-open` if you want the CLI to print the page URL without opening it automatically.

## Add from another command

Pipe a single value into a single variable name when another program produces the secret:

```bash theme={null}
command-that-produces-the-value | capy add API_KEY --json
```

Replace `command-that-produces-the-value` with your actual producer. This keeps the value out of Capy's command-line arguments. The JSON result reports the operation without printing the value. An existing name is refused unless you pass `--force`; use [`capy edit`](/docs/cli/edit) when you intend to update an existing secret.

## Save locally before sharing

Add `--no-push` to write the encrypted value to `.env` without syncing it yet:

```bash theme={null}
capy add API_KEY --no-push
# When ready to share the local changes:
capy push
```

Review and commit any resulting `keep.lock` changes with your project. Keep `.env` gitignored.

## Check the result

```bash theme={null}
capy list
```

This lists variable names and connector metadata without exposing values. Your application can read the new value when you launch it with [`capy run`](/docs/using/running-your-app).

`capy add` requires a cloud or BYOC project; it is unavailable in local-only mode.

## See also

* [`capy add` reference](/docs/cli/add) — all options
* [Editing secrets](/docs/using/editing-secrets) — update existing values
* [Removing secrets](/docs/using/removing-secrets) — remove values from a branch


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.