Using accio
accio runs a command with a project's secrets as environment variables. The values never go into a file, so nothing is left on disk for a person or an agent to read.
Run a command
accio my-app npm run dev
The command gets the secrets in shared and in my-app. If both have a key with the same name, the one in my-app wins.
To use accio from your package.json scripts, put it in front of the command: "dev": "accio my-app next dev". The dev server gets its keys without a .env.
Options go right after the project name. If the command itself starts with a dash, put -- before it.
| Option | What it does |
|---|---|
--require NAME1,NAME2 | Stops before running if the project is missing any of these keys, and names the missing ones. |
--no-mask | Shows output exactly as the command wrote it. See What agents see. |
A file secret, such as a .p8 key, arrives as the path to a temporary copy of the file. The copy is deleted when the command ends.
See what a project holds
accio listlists your projects.accio list my-applists the key names the command would get, and marks keys that come fromshared, keys that overrideshared, and keys accio won't conceal.- Add
--jsonfor output a script can read.
accio list shows names only, never values.
Import and export
accio import [project] [file]opens Fidelius's Import preview for a.envfile. Nothing is saved until you click Import. See Projects and secrets.accio export [project] [file]opens Fidelius's Export preview, andaccio export --examplewrites a.env.examplewith names only. See Exporting a .env.
Without a project name, both use the name of the folder you're in.
Tab completion
accio completion zsh (or bash, fish) prints the completion script. Get started shows where to put it.
Project names accio reserves
A project can't be named list, help or completion, and new projects can't be named import or export, because accio reads those words as commands.