Your secure foundation for effortless secrets management
Centralize, secure, and sync all your application secrets effortlessly. Manage team access, integrate via CLI & GitHub, and accelerate your deployments with confidence.
Secrets Management, Simplified
Shelve provides the secure, central platform you need for effortless secrets management. Bring all your API keys, tokens, and environment variables into one organized dashboard. Sync them seamlessly across stages using our powerful CLI and GitHub integration, ensuring your team always has the right configuration.
Secrets injection
CLI Access Api Keys
npx nypm add -D @shelve/cli
Envelope encryption, per project
Every variable is encrypted with a per-project Data Encryption Key (DEK), itself sealed by a platform Key Encryption Key (KEK). A leaked DEK scopes the blast radius to a single project, and rotating keys never touches your application code.
Scoped, expiring API tokens
Stop shipping broad-power tokens. Create tokens scoped to specific teams, projects, environments, or permissions — with optional expiry and IP allowlists. Tokens are shown once, stored hashed, and every usage lands in the audit log.
Audit everything that matters
Team changes, project writes, variable edits, token creations — every security-relevant action is captured with actor, IP, user agent, and resource context. Query the feed via API, filter by action, and build your own alerting on top.
Safe with your AI coding agent
Shelve treats AI agents as first-class citizens. shelve init provisions .cursorignore, .aiderignore, .codeiumignore, and more so your coding agent never reads a raw .env file. Tokens live in the OS keychain. Runtime injection keeps secrets in memory only.
Ensure Environment Parity
Stop runtime errors caused by missing variables. Shelve detects inconsistencies across your environments instantly.
Built for Seamless Teamwork
Invite team members, manage access with clear roles (Owner, Admin, Member), and ensure everyone works with the correct, up-to-date configuration without compromising security.
Keep GitHub Secrets Synced, Effortlessly
Connect your Shelve projects to GitHub repositories via our official GitHub App. Automatically keep your GitHub Actions secrets and repository secrets perfectly synchronized with your single source of truth in Shelve, eliminating manual updates.
Command Everything
Hit Cmd+K (or Ctrl+K) to unlock Shelve's command center. Instantly search, navigate, and execute actions across your entire workspace—from switching projects to managing secrets. The ultimate shortcut to peak productivity.
Frequently Asked Questions
Is Shelve free?
Shelve is open source and free to self-host. The hosted instance at app.shelve.cloud is currently free to use, and every security feature on this page — envelope encryption, scoped tokens, audit logs, and agent-safe ignore files — ships in the open-source core.
How does Shelve encrypt my secrets? Shelve uses a two-tier envelope encryption scheme. Each variable is sealed with a per-project Data Encryption Key (DEK) using AES-256-GCM, and the DEK itself is sealed with a platform-wide Key Encryption Key (KEK). Plaintext never lands in the database. Read the full model on the Encryption page.
Can I self-host Shelve? Absolutely. Shelve is designed for flexibility, including self-hosting. You can deploy your own instance using Vercel, and more providers are coming soon.
Does Shelve integrate with other tools?
Yes. Native synchronization with GitHub Secrets is available today, and shelve run injects variables into any CI, container, or process without writing a .env file. More integrations are actively in development.
Streamline your workflow this afternoon
Imagine your workflow, just smoother and more secure. That’s the developer experience Shelve is built to deliver.