Organization (my-company) │ ├── Project (api) │ ├── dev │ │ ├── DATABASE_URL = postgres://localhost/mydb │ │ ├── API_KEY = sk-dev-xxx │ │ └── AUTH_SECRET = random-dev-key │ ├── preview │ │ ├── DATABASE_URL = postgres://preview-host/mydb │ │ └── API_KEY = sk-preview-xxx │ └── prod │ ├── DATABASE_URL = postgres://prod-host/mydb │ └── API_KEY = sk-live-xxx │ └── Project (web) ├── dev │ └── NEXT_PUBLIC_API_URL = http://localhost:3001 └── prod └── NEXT_PUBLIC_API_URL = https://api.example.com
sigillo orgs # the organization's ID sigillo projects create --org <ORG_ID> --name my-app
dev, preview and prod.--project, SIGILLO_PROJECT), and refuses a name that more than one project you can see has: use the ID then.-c takes.KEY=value lines, with quotes, export and comments, into the current environment. If one name in it isn't valid, nothing is imported.sigillo secrets # names; in a terminal, also which are empty or missing sigillo secrets get DATABASE_URL --raw # one value sigillo secrets set API_KEY sk-live-xxx # set a value sigillo secrets set API_KEY -c dev -c preview # several environments; asks for the value echo "multiline\nvalue" | sigillo secrets set CERT # from stdin sigillo secrets delete OLD_KEY # delete
secrets set asks for it without showing it, and an empty answer sets an empty secret to fill in later..env.<slug>, and Copy as .env puts it on the clipboard. In a protected environment, both are recorded as downloads.sigillo secrets download --format env > .env
| Format | Use case |
json | Application config files |
env | Shell scripts with quotes |
env-no-quotes | Shell scripts without quotes |
yaml | The default |
docker | Docker --env-file |
dotnet-json | .NET appsettings.json (uses __ for nested keys) |
xargs | NUL-delimited pairs for shell pipelines |
sigillo audit verify checks; a row marked unsigned was added to the database around it. See the signed history.