Run these commands from your Capy-managed project. Check the active secret branch and its variable names first:
Remove a value
Capy asks you to confirm before removing the value from the active branch. On success, it updates .env, keep.lock, and the remote branch. You do not need a separate capy push.
To remove several values together:
Every supplied name must exist on the active branch. If a value being removed has an unpushed local edit, Capy refuses rather than silently discarding it. Resolve that edit with capy or push the intended value, then retry the removal.
Remove without a prompt
For an already-approved automated operation, explicitly pass --yes:
--json and non-interactive execution require --yes; they do not implicitly approve deletion.
Finish the change
Run capy list again to check the active branch, then review and commit the keep.lock changes. Update application code or configuration that still expects the removed variable.
Removing a value from Capy does not revoke the credential at its provider or erase copies already held by running processes or deployment targets. Revoke the provider credential separately when it should no longer work, and update affected deployments.
capy remove requires a cloud or BYOC project; it is unavailable in local-only mode.
See also
Last modified on October 2, 2026