Your secure foundation for effortless secrets management

Centralize, secure, and sync all your application secrets effortlessly. Manage team access, integrate via CLI & GitHub, and accelerate your deployments with confidence.

Secrets Management, Simplified

Shelve provides the secure, central platform you need for effortless secrets management. Bring all your API keys, tokens, and environment variables into one organized dashboard. Sync them seamlessly across stages using our powerful CLI and GitHub integration, ensuring your team always has the right configuration.

Secrets injection

CLI Access Api Keys

npx nypm add -D @shelve/cli

Envelope encryption, per project

Every variable is encrypted with a per-project Data Encryption Key (DEK), itself sealed by a platform Key Encryption Key (KEK). A leaked DEK scopes the blast radius to a single project, and rotating keys never touches your application code.

Scoped, expiring API tokens

Stop shipping broad-power tokens. Create tokens scoped to specific teams, projects, environments, or permissions — with optional expiry and IP allowlists. Tokens are shown once, stored hashed, and every usage lands in the audit log.

Audit everything that matters

Team changes, project writes, variable edits, token creations — every security-relevant action is captured with actor, IP, user agent, and resource context. Query the feed via API, filter by action, and build your own alerting on top.

Safe with your AI coding agent

Shelve treats AI agents as first-class citizens. shelve init provisions .cursorignore, .aiderignore, .codeiumignore, and more so your coding agent never reads a raw .env file. Tokens live in the OS keychain. Runtime injection keeps secrets in memory only.

Ensure Environment Parity

Stop runtime errors caused by missing variables. Shelve detects inconsistencies across your environments instantly.

Built for Seamless Teamwork

Invite team members, manage access with clear roles (Owner, Admin, Member), and ensure everyone works with the correct, up-to-date configuration without compromising security.

Keep GitHub Secrets Synced, Effortlessly

Connect your Shelve projects to GitHub repositories via our official GitHub App. Automatically keep your GitHub Actions secrets and repository secrets perfectly synchronized with your single source of truth in Shelve, eliminating manual updates.

Command Everything

Hit Cmd+K (or Ctrl+K) to unlock Shelve's command center. Instantly search, navigate, and execute actions across your entire workspace—from switching projects to managing secrets. The ultimate shortcut to peak productivity.

Frequently Asked Questions

Is Shelve free? Shelve is open source and free to self-host. The hosted instance at app.shelve.cloud is currently free to use, and every security feature on this page — envelope encryption, scoped tokens, audit logs, and agent-safe ignore files — ships in the open-source core.

How does Shelve encrypt my secrets? Shelve uses a two-tier envelope encryption scheme. Each variable is sealed with a per-project Data Encryption Key (DEK) using AES-256-GCM, and the DEK itself is sealed with a platform-wide Key Encryption Key (KEK). Plaintext never lands in the database. Read the full model on the Encryption page.

Can I self-host Shelve? Absolutely. Shelve is designed for flexibility, including self-hosting. You can deploy your own instance using Vercel, and more providers are coming soon.

Does Shelve integrate with other tools? Yes. Native synchronization with GitHub Secrets is available today, and shelve run injects variables into any CI, container, or process without writing a .env file. More integrations are actively in development.

Streamline your workflow this afternoon

Imagine your workflow, just smoother and more secure. That’s the developer experience Shelve is built to deliver.