Centralize your secrets.
Sync everywhere, instantly.
Keel is a secrets manager for developers: one encrypted system of record for the API keys, tokens, and environment variables behind development, staging, and production.
Your secrets are everywhere.
Scattered across files, pipelines, and providers - until there's one place they all point to.
One place for every secret.
Manage environments, credentials, machine identities, and access from a single system.
From code to production.
The infrastructure layer connecting every stage.
Works where your code lives.
Injected at runtime
Secrets never touch disk. They're loaded into the process environment and gone when it exits.
Built for secrets.
Encryption
AES-256-GCM encryption at rest, HTTPS in transit.
RBAC
Owner, admin, member, and viewer roles, plus per-environment grants.
Audit Logs
Reads, changes, and denied attempts, attributed and timestamped.
Short-lived sessions
CLI access tokens last one hour, with rotating refresh tokens.
Environment Isolation
Members and viewers only reach the environments they are granted.
Version history
Every change is kept, and any earlier value can be restored.
One layer, every consumer.
A single centralized system for secrets - read by developers, pipelines, and infrastructure alike.
What Keel does, and why it is built this way.
Features
- Secrets managementOne encrypted place for API keys, tokens, and credentials, organised by project and environment.
- Environment variablesSeparate Development, Staging, and Production values, with .env import and export.
- Version historyNumbered versions for every change, with restore to any earlier value.
- Access controlOwner, admin, member, and viewer roles, plus explicit per-environment grants.
- Audit loggingAn append-only record of secret changes, reveals, exports, and access decisions.
Guides
- What is secrets management? A practical guide for developersSecrets management is how you store, distribute, and control access to credentials such as API keys and database passwords. Here is what it covers and where to start.
- Environment variables vs. secrets: what is the difference?Environment variables are a way to deliver configuration. Secrets are a kind of value that needs protection. Here is how the two overlap and why it matters.
- How to keep secrets out of Git repositoriesPrevent API keys and passwords from reaching Git with ignore rules, scanners, and push protection, and learn the correct cleanup order if one gets committed.
Frequently asked questions
- What is Keel?
- Keel is a secrets manager for developers. It stores API keys, tokens, and environment variables in one encrypted workspace, separated by project and environment, with role-based access and a record of every change.
- How are my secrets protected?
- Values are encrypted at rest with AES-256-GCM, and every read passes a server-side check of your role and environment access before anything is decrypted. See how secrets are stored.
- Can I bring my existing .env files?
- Yes. Import parses the file in your browser, shows a preview without values, and saves nothing until you confirm. See environment variable management.
- Can I limit who sees production?
- Yes. Members and viewers have no environment access until an admin grants it, and Production is not special-cased. See access control.
- Does Keel rotate secrets automatically?
- Not yet. You change a value yourself, and Keel keeps the earlier versions so you can restore one if needed.
- Does it work with Vercel?
- Admins can connect a Vercel project and push secrets to its environment variables. The integration is new, so check the result in Vercel after your first sync.