Keel documentation
Keel stores application secrets encrypted, keeps them separate per environment, controls who can read them, and records every change. These docs describe what Keel does today, including its current limits.
Recommended path
If you are new, read these in order. Each page links to the next.
Getting Started
- IntroductionWhat Keel is, the problem it solves, who it is for, and how it fits into a developer's workflow.
- Core conceptsThe projects, environments, secrets, versions, roles, integrations and audit logs Keel is built from, and how they relate.
- QuickstartGo from a new account to a local application running with secrets injected from Keel, in about ten minutes.
- Your first projectHow to create a Keel project, name it, choose environments, and set it up sensibly from the start.
- Your first secretCreate, view, update, mask and delete a secret, with the permissions each action needs and how version history works.
Core Features
- Managing secretsCreate, update, delete, search and safely handle secrets in Keel, including special characters, multiline values and masking.
- EnvironmentsHow Keel separates development, staging and production values, who can access each, and how to avoid using production credentials by mistake.
- Version history and rollbackHow Keel records every value change, how to inspect old versions, and how restoring a version works, with the permissions and caveats involved.
- Projects and access controlRoles, per-environment access, inviting members and troubleshooting permission errors in Keel.
- Audit logsWhich events Keel records, how to inspect and filter them, what each entry contains, and how to investigate unexpected changes.
- Import and exportBring an existing .env file into a Keel environment and export an environment back to a .env file, including the supported syntax and limits.
- IntegrationsWhich integrations Keel supports today, what they need, and how synchronization and disconnection behave.
- Vercel integrationConnect a Vercel account, map Keel environments to Vercel targets, sync secrets, redeploy automatically, and handle sync failures.
CLI and Runtime
- CLI installationRequirements and steps to build and install the Keel CLI from source, verify the version, and fix common installation problems.
- CLI authenticationHow keel login works, where credentials are stored, how tokens expire and renew, and how to log out or revoke a session.
- Project initializationUse keel init to link a local directory to a Keel project and environment, and understand the generated .keel.json file.
- Retrieving and setting secretsList secret keys, create and update secrets with the Keel CLI, select an environment, and understand permissions and errors.
- Runtime secret injectionRun any command with Keel secrets in its environment using keel run, and understand how it works, what it protects, and how failures behave.
API Reference
- API overviewBase URL, authentication, request and response conventions, rate limits and the authorization model of the Keel HTTP API.
- Authentication endpointsThe device authorization flow and CLI session endpoints used to sign the Keel CLI in, refresh its tokens and revoke sessions.
- Projects and environments APIEndpoints to list, create, read, update and delete projects, including how environments and permissions are returned.
- Secrets APIEndpoints to list, create, read, update and delete secrets, view and restore versions, and import and export an environment.
- Members, access and invitations APIEndpoints to list and manage project members, send and accept invitations, and grant or revoke environment access.
- Audit and integrations APIEndpoints for the project audit log, the security overview, and the Vercel integration, with parameters and response shapes.
- Error codesThe HTTP status codes and error response shape the Keel API returns, with the messages you will see and what to do about them.
Security
- Security modelHow Keel encrypts, authenticates, authorizes and audits access to secrets, what the server and client each see, and where the current limits are.
- Environment variable best practicesPractical rules for handling secrets with Keel, from keeping them out of Git to rotating compromised credentials and restricting access.
- TroubleshootingDiagnose login failures, permission errors, missing projects, CLI configuration problems, network errors, integration sync failures and failed deployments.
Reference
- Environment variables referenceEvery environment variable used to deploy and operate the Keel server and CLI, with format, sensitivity and where each is read.
- GlossaryShort definitions of the terms Keel uses, from projects and environments to device codes and audit events.
- FAQAnswers to common questions about what Keel is, how it protects secrets, how environments and rollback work, and what happens if Keel is unavailable.