Skip to main content

envshed share

Share secret values with people outside your team through expiring, encrypted links. A share link is a snapshot of the selected values at the time it was created; opening it never requires an Envshed account.

See Share Links for how the links are protected and what the recipient sees.

Subcommands​

SubcommandDescription
create (default)Create a share link for secrets in an environment
listList share links in an organization
revokeRevoke a share link
openOpen a share link and print its secrets (no login required)

create is the default subcommand, so envshed share DATABASE_URL is the same as envshed share create DATABASE_URL. If a secret is literally named list, revoke, open, or create, spell out envshed share create <KEY>.


share create​

envshed share [create] [KEY...] [options]

Creates a link for the given keys in the current environment. With no keys, every shareable secret in the environment is included (you are asked to confirm unless --yes is passed). Placeholders and disabled secrets have no shareable value and are skipped; the command lists them after creating the link.

Requires read access to the environment, like envshed pull.

Options​

FlagDescriptionDefault
-o, --org <slug>Organization slugfrom .envshed.json
-p, --project <slug>Project slugfrom .envshed.json
-e, --env <slug>Environment slugfrom .envshed.json / ENVSHED_ENV
--expires <duration>Lifetime: minutes, or a number with m, h, or d (e.g. 15m, 8h, 7d). Maximum 30d24h
--burnOne-time link: it self-destructs after the first openoff
--max-views <n>Maximum number of opens (ignored when --burn is set)unlimited until expiry
--passwordProtect the link with a password. Prompted interactively, or read from stdin when pipedoff
--note <text>Note shown to the recipient and in the share links listnone
-y, --yesSkip the confirmation when sharing every secret in the environmentoff
--output jsonPrint the created link as JSONtable

Examples​

# One-time link to a single value, valid for one hour
$ envshed share DATABASE_URL --expires 1h --burn

my-org / my-project / staging

✔ Share link created

URL https://app.envshed.com/s/3f1c…#Qm9…
Expires 9/6/2026, 10:15:00 AM
Views one-time (destroyed after the first open)
Password none

Copy the URL now: it cannot be shown again.
# Several keys, password protected, valid for 3 days
envshed share STRIPE_KEY STRIPE_WEBHOOK_SECRET --expires 3d --password --note "for the payments contractor"

# Everything in the environment, max 5 opens, no prompt
envshed share --max-views 5 --yes

# Script-friendly: password from stdin, JSON output
echo "$SHARE_PASSWORD" | envshed share API_KEY --password --output json

The URL contains the decryption key after #. It is shown once: Envshed stores only a hash of it and cannot reconstruct the link later.


share list​

envshed share list [options]

Lists share links in the organization. Owners and admins see every link; other members see the links they created.

Options​

FlagDescription
-o, --org <slug>Organization slug
--output jsonPrint the full list as JSON

Example​

$ envshed share list

┌──────────────────────────────────────┬──────────────────────┬─────────┬───────┬───────────────────────┬───────────────┐
│ ID │ Secrets │ Status │ Views │ Expires │ Created by │
├──────────────────────────────────────┼──────────────────────┼─────────┼───────┼───────────────────────┼───────────────┤
│ 3f1c9a2e-… │ DATABASE_URL │ active │ 0 / 1 │ 9/6/2026, 10:15:00 AM │ Ana │
└──────────────────────────────────────┴──────────────────────┴─────────┴───────┴───────────────────────┴───────────────┘

share revoke​

envshed share revoke <id> [options]

Revokes a link immediately and wipes its encrypted payload. Only the creator or an organization owner/admin can revoke a link. Prompts for confirmation unless --yes is passed.

Options​

FlagDescription
<id>Share link ID (from share list or the dashboard)
-o, --org <slug>Organization slug
-y, --yesSkip the confirmation prompt
--output jsonPrint JSON output

share open​

envshed share open <url> [options]

Opens a share link from the terminal and prints its secrets in .env format. No login or configuration is needed: the command talks to the Envshed instance named in the URL. Quote the URL, since the # would otherwise start a shell comment.

Opening a link counts as a view. For one-time links the command asks for confirmation first (skip with --yes); once opened, the link is destroyed.

Options​

FlagDescription
<url>The share link, e.g. https://app.envshed.com/s/<id>#<key> (or the bare <id>#<key>)
--file <path>Write the secrets to a file (created with mode 0600) instead of stdout
-y, --yesSkip the one-time-link confirmation
--output jsonPrint the full response as JSON

Examples​

# Print to the terminal (a reminder about terminal history is printed to stderr)
envshed share open "https://app.envshed.com/s/3f1c9a2e-…#Qm9…"

# Straight into a .env file
envshed share open "https://app.envshed.com/s/3f1c9a2e-…#Qm9…" --file .env

# Password-protected link in a script
echo "$SHARE_PASSWORD" | envshed share open "https://app.envshed.com/s/…#…" --yes > .env

See Also​