Skip to content

API

Use the API when you want to script secret operations in TypeScript. If you want prompting, initialization, or store selection, prefer the CLI.

If you want to add a new store provider, implement these two interfaces from @lazyenv/core.

The runtime CRUD interface used by commands like sync, pull, get, list.

export interface SecretStore {
readonly name: string;
listProjects(): Promise<Project[]>;
listConfigs(project: string): Promise<Config[]>;
projectExists(project: string): Promise<boolean>;
setupProject(project: string, config: string): Promise<void>;
listSecrets(project: string, config: string, folder?: string): Promise<string[]>;
getSecret(project: string, config: string, key: string, folder?: string): Promise<string | undefined>;
setSecret(project: string, config: string, key: string, value: string, folder?: string): Promise<void>;
setSecrets(project: string, config: string, secrets: Record<string, string>, folder?: string): Promise<void>;
deleteSecret(project: string, config: string, key: string, folder?: string): Promise<void>;
deleteSecrets(project: string, config: string, keys: string[], folder?: string): Promise<void>;
}

The interactive/setup interface used by lazyenv init (listing/creating projects/configs and provider-specific links).

export interface SecretStoreAdmin {
readonly provider: SecretStoreProvider;
readonly capabilities: {
listProjects: boolean;
listConfigs: boolean;
createProject: boolean;
createConfigs: boolean;
};
readonly missingConfigsPolicy: 'allow' | 'error' | 'create';
assertReady(): void;
getTokenUrl?(): string | null;
getProjectUrl?(projectId: string): string | null;
listProjects?(): Promise<Project[]>;
listConfigs?(projectId: string): Promise<Config[]>;
createProject?(input: { name: string }): Promise<{ projectId: string; projectName: string; organizationId?: string }>;
createConfigs?(input: { projectId: string; configs: Array<{ slug: string; name?: string }> }): Promise<void>;
}
Terminal window
pnpm add lazyenv
import { LazyenvClient } from 'lazyenv';
const client = new LazyenvClient({
store: 'infisical', // or 'doppler' | 'bitwarden' | 'onepassword'
projectId: '...',
environment: 'dev',
token: process.env.INFISICAL_API_TOKEN,
});
await client.pull({ outputFile: '.env' });
await client.setSecrets({ API_KEY: 'value' });
await client.deleteSecrets(['OLD_KEY']);
const secrets = await client.list({ showValues: true });
const value = await client.get('API_KEY');
await client.add('API_KEY', 'value');
await client.delete('OLD_KEY');
new LazyenvClient({
store: 'infisical',
projectId: '...',
environment: 'dev',
folder: '/apps/web',
token: process.env.INFISICAL_API_TOKEN,
siteUrl: process.env.INFISICAL_API_URL, // infisical only
});
const folders = await client.detectWorkspace();
const config = await client.loadConfig();