Manage shared environment variables
A practical workspace for teams that have outgrown copying .env files between laptops, chat threads, and deployment systems.
Read the guideRunEnv is an environment-variable and secret-management platform for teams. Inject authorized secrets at runtime instead of passing .env files around, and let coding agents take approved actions without standing credentials.

RunEnv solutions
Explore the workflows teams use when shared .env files stop being enough: team management, version control, rollback, runtime injection, and Agent Guard for coding agents.
A practical workspace for teams that have outgrown copying .env files between laptops, chat threads, and deployment systems.
Read the guideKeep configuration changes reviewable and recovery close when a deployment depends on the right environment variables.
Read the guideDeliver the configuration a process needs at execution time while keeping the no-file boundary explicit for the runtime-injection workflow.
Read the guideConnect Codex, Claude, Copilot, or Cursor through Agent Guard so a coding agent can preview and execute approved work without holding standing credentials.
Read the guideCompare and how-to
Comparison pages state what RunEnv does today. How-to pages walk the supported CLI, CI, and Agent Guard paths, including the disk and credential limits.
01 / Bootstrap once
Quickstart detects a local command, links the project and environment, and hands back the next command without turning the demo into a real shell session.
Read the CLI guiderunenv quickstartQuickstart is selected. Press Run demo to see it in action, or choose another flow above.
Simulated in your browser. No command is executed.
An interactive reproduction of the RunEnv dashboard’s environment diff workflow using masked, fictional values only.
Compare secret differences between two environments and copy values.
Showing 13 of 13
03 / Promote with intent
RunEnv supports environment promotion with snapshots and approval rules so a developer’s change can move quickly without losing the control point.
Move selected changes through a controlled environment path.
| Selected changes | Policy |
|---|---|
PAYMENTS_API_URLChanged | approved scope |
FEATURE_BILLING_V2New | approved scope |
SENTRY_TRACES_SAMPLE_RATEChanged | approved scope |
04 / Bound every agent
Agent Access Packs are scope- and TTL-bound. Agent Guard adds policy, approval, and tamper-evident receipts around the action itself.
Explore agent integrationsRuntime delivery pack
Limits one agent to selected keys, one environment, and a short-lived session.
05 / Keep recovery close
Environment snapshots and audit history let teams understand the delta first, then take a deliberate rollback action when it is needed.
Restoring creates a new version and preserves this snapshot in the audit history.
The operational surface
Secret inventory, environment context, audit controls, members, and access settings meet in the operational surface teams use every day.

Authentic product interface. Secret values in the screenshot are masked.
Create an account, connect a project, and use Quickstart to choose the next safe command for your local workflow.
FAQ
Direct answers for search and answer engines, including the disk and agent-access limits.