CLI Commands
Shared flags and resolution rules live in CLI Options.
Initialize a repo: scan for .env.example files and write .lazyenv/config.json.
lazyenv init --store <infisical|doppler|bitwarden|onepassword>Command-specific flags:
| Flag | Meaning |
|---|---|
--project <name> | Project name/slug |
--project-id <id> | Use an existing project identifier (store-specific) |
--environments <envs> | Comma-separated environments (e.g. dev,staging,prod) |
--create | Create the project when supported (non-interactive only; requires --project) |
Sync keys from .env.example into your store.
lazyenv syncCommand-specific flags:
| Flag | Meaning |
|---|---|
--dry-run | Print planned actions without writing secrets or running provisioners |
--skip-unspecified | Skip keys not present in .env.example |
--rotate | Rotate secrets for rules that opt into rotation (onExists=rotate) |
--rotate-match <pattern> | Only rotate/provision keys matching a RegExp string |
--promote-global | Copy successfully used global provisioners into .lazyenv/config.json (useful for CI) |
--targets | Run all configured targets after a successful store sync |
--target <name> | Run a named target after a successful store sync (repeatable) |
Pull secrets from your store and write .env files.
lazyenv pullNotes:
pullalso resolves configuredimportsfor each folder (read-through).
Run a command with secrets injected as environment variables.
lazyenv run -- <command...>Notes:
- If the store is unavailable,
lazyenv runcan fall back to local.envfiles. runalso resolves configuredimportsfor the current folder (read-through).
Add a key/value to the store and update .env.example.
lazyenv add <key> [value]Command-specific flags:
| Flag | Meaning |
|---|---|
--value <value> | Alternative to positional value |
--all-environments | Add to all configured environments |
delete
Section titled “delete”Delete a key from the store and remove it from .env.example.
lazyenv delete <key>Command-specific flags:
| Flag | Meaning |
|---|---|
--force | Skip confirmation |
--all-environments | Delete from all configured environments |
List secrets in the project.
lazyenv listCommand-specific flags:
| Flag | Meaning |
|---|---|
--json | JSON output |
--show-values | Include values in output |
Get a single secret value.
lazyenv get <key>Command-specific flags:
| Flag | Meaning |
|---|---|
--json | JSON output |
migrate
Section titled “migrate”Migrate secrets between stores.
lazyenv migrate --to <infisical|doppler|bitwarden|onepassword>Command-specific flags:
| Flag | Meaning |
|---|---|
--from <store> | Source store (defaults to .lazyenv/config.json store) |
--project-from <id> | Source project identifier (defaults to .lazyenv/config.json projectId) |
--project-to <id> | Target project identifier |
--from-envs <envs> | Comma-separated source envs/configs |
--env-mappings <json> | JSON env mapping |
--auto-map | Auto-map env aliases (prd/production→prod) |
--folders <paths> | Comma-separated workspace folder paths |
--organization-id <id> | Infisical org id (required when updating config to store=infisical) |
--no-update-config | Do not update .lazyenv/config.json after migration |
Dev-only helpers for stable ports and derived URLs.
lazyenv dev portslazyenv dev statusLaunch the interactive terminal UI.
lazyenv tuiprovisioners
Section titled “provisioners”Manage provisioners and provisioner rules.
lazyenv provisioners listlazyenv provisioners bind <KEY>lazyenv provisioners test <NAME>Open the current project in your browser.
lazyenv opentargets
Section titled “targets”Targets are sinks for fan-out:
github: upsert GitHub repo secretsstore: mirror selected keys into another store/project/path
lazyenv targets createlazyenv targets listlazyenv targets run <NAME>Command-specific flags:
| Flag | Meaning |
|---|---|
--yes | Non-interactive mode; requires needed values in env vars |
--env <environment> | Source environment used for store targets |
imports
Section titled “imports”Manage cross-project imports (compose/read-through only).
lazyenv imports add --from ../.lazyenv/config.json --source-folder . --target-folder apps/web --keys BETTER_AUTH_SECRETlazyenv imports listlazyenv imports validatecomplete
Section titled “complete”Generate shell completion scripts.
lazyenv complete zshlazyenv complete bashlazyenv complete fishlazyenv complete powershellSee: Shell Completions.