Skip to content

Switching Stores

lazyenv supports multiple secret stores (infisical, doppler, bitwarden, onepassword). Use lazyenv migrate to copy secrets and optionally update .lazyenv/config.json.

  • Default store is set in .lazyenv/config.json as store.
  • Most commands accept --store <store> to override per command.
Terminal window
export INFISICAL_API_TOKEN="st.xxx"
export DOPPLER_TOKEN="dp.st.xxx"
# Uses .lazyenv/config.json store + projectId as the source by default.
lazyenv migrate --to doppler --project-to my-doppler-project --auto-map --force
Terminal window
export DOPPLER_TOKEN="dp.st.xxx"
export INFISICAL_API_TOKEN="st.xxx"
lazyenv migrate --from doppler --to infisical \
--project-from my-doppler-project \
--project-to xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx \
--organization-id xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx \
--auto-map --force

Notes:

  • If you omit --from, it defaults to .lazyenv/config.json store.
  • If you omit --project-from, it defaults to .lazyenv/config.json projectId.
  • When switching to Infisical and updating config, you must provide --organization-id (or have it set already).

See lazyenv migrate for all options.

After migration, spot-check a few secrets and folders:

Terminal window
lazyenv list --env dev
lazyenv get DATABASE_URL --folder apps/web

lazyenv keeps your workspaceFolders[*].secretPath as the source of truth for folder layout:

  • Infisical uses native folder paths like /apps/web.
  • Doppler uses prefixes derived from the last path segment (e.g. /apps/web -> WEB__).

Examples:

Folder PathDoppler PrefixExample Secret
/(none)DATABASE_URL
/apps/webWEB__WEB__DATABASE_URL
/apps/apiAPI__API__JWT_SECRET