envshed share
Share secret values with people outside your team through expiring, encrypted links. A share link is a snapshot of the selected values at the time it was created; opening it never requires an Envshed account.
See Share Links for how the links are protected and what the recipient sees.
Subcommands
| Subcommand | Description |
|---|---|
create (default) | Create a share link for secrets in an environment |
list | List share links in an organization |
revoke | Revoke a share link |
open | Open a share link and print its secrets (no login required) |
create is the default subcommand, so envshed share DATABASE_URL is the same as envshed share create DATABASE_URL. If a secret is literally named list, revoke, open, or create, spell out envshed share create <KEY>.
share create
envshed share [create] [KEY...] [options]
Creates a link for the given keys in the current environment. With no keys, every shareable secret in the environment is included (you are asked to confirm unless --yes is passed). Placeholders and disabled secrets have no shareable value and are skipped; the command lists them after creating the link.
Requires read access to the environment, like envshed pull.
Options
| Flag | Description | Default |
|---|---|---|
-o, --org <slug> | Organization slug | from .envshed.json |
-p, --project <slug> | Project slug | from .envshed.json |
-e, --env <slug> | Environment slug | from .envshed.json / ENVSHED_ENV |
--expires <duration> | Lifetime: minutes, or a number with m, h, or d (e.g. 15m, 8h, 7d). Maximum 30d | 24h |
--burn | One-time link: it self-destructs after the first open | off |
--max-views <n> | Maximum number of opens (ignored when --burn is set) | unlimited until expiry |
--password | Protect the link with a password. Prompted interactively, or read from stdin when piped | off |
--note <text> | Note shown to the recipient and in the share links list | none |
-y, --yes | Skip the confirmation when sharing every secret in the environment | off |
--output json | Print the created link as JSON | table |
Examples
# One-time link to a single value, valid for one hour
$ envshed share DATABASE_URL --expires 1h --burn
my-org / my-project / staging
✔ Share link created
URL https://app.envshed.com/s/3f1c…#Qm9…
Expires 9/6/2026, 10:15:00 AM
Views one-time (destroyed after the first open)
Password none
Copy the URL now: it cannot be shown again.
# Several keys, password protected, valid for 3 days
envshed share STRIPE_KEY STRIPE_WEBHOOK_SECRET --expires 3d --password --note "for the payments contractor"
# Everything in the environment, max 5 opens, no prompt
envshed share --max-views 5 --yes
# Script-friendly: password from stdin, JSON output
echo "$SHARE_PASSWORD" | envshed share API_KEY --password --output json
The URL contains the decryption key after #. It is shown once: Envshed stores only a hash of it and cannot reconstruct the link later.
share list
envshed share list [options]
Lists share links in the organization. Owners and admins see every link; other members see the links they created.
Options
| Flag | Description |
|---|---|
-o, --org <slug> | Organization slug |
--output json | Print the full list as JSON |
Example
$ envshed share list
┌──────────────────────────────────────┬──────────────────────┬─────────┬───────┬───────────────────────┬───────────────┐
│ ID │ Secrets │ Status │ Views │ Expires │ Created by │
├──────────────────────────────────────┼──────────────────────┼─────────┼───────┼───────────────────────┼───────────────┤
│ 3f1c9a2e-… │ DATABASE_URL │ active │ 0 / 1 │ 9/6/2026, 10:15:00 AM │ Ana │
└──────────────────────────────────────┴──────────────────────┴─────────┴───────┴───────────────────────┴───────────────┘
share revoke
envshed share revoke <id> [options]
Revokes a link immediately and wipes its encrypted payload. Only the creator or an organization owner/admin can revoke a link. Prompts for confirmation unless --yes is passed.
Options
| Flag | Description |
|---|---|
<id> | Share link ID (from share list or the dashboard) |
-o, --org <slug> | Organization slug |
-y, --yes | Skip the confirmation prompt |
--output json | Print JSON output |
share open
envshed share open <url> [options]
Opens a share link from the terminal and prints its secrets in .env format. No login or configuration is needed: the command talks to the Envshed instance named in the URL. Quote the URL, since the # would otherwise start a shell comment.
Opening a link counts as a view. For one-time links the command asks for confirmation first (skip with --yes); once opened, the link is destroyed.
Options
| Flag | Description |
|---|---|
<url> | The share link, e.g. https://app.envshed.com/s/<id>#<key> (or the bare <id>#<key>) |
--file <path> | Write the secrets to a file (created with mode 0600) instead of stdout |
-y, --yes | Skip the one-time-link confirmation |
--output json | Print the full response as JSON |
Examples
# Print to the terminal (a reminder about terminal history is printed to stderr)
envshed share open "https://app.envshed.com/s/3f1c9a2e-…#Qm9…"
# Straight into a .env file
envshed share open "https://app.envshed.com/s/3f1c9a2e-…#Qm9…" --file .env
# Password-protected link in a script
echo "$SHARE_PASSWORD" | envshed share open "https://app.envshed.com/s/…#…" --yes > .env
See Also
- Share Links — how links are protected, limits, and audit trail
envshed secret— read and write individual secrets