API

Fetch the ciphertext. Decrypt it yourself.

The EnvVault API is read-only. Each vault has an account URL and one or more account tokens. A token downloads an encrypted envelope by the secret's name. It cannot open the envelope, and it cannot upload a new one. Keep the decryption key beside the token, not inside it.

Your account URL

Every secret is reachable at https://mvault.net/v1/api/ followed by its name. The name is made URL-friendly when you create the secret, so "Production API" becomes production-api. Create a token on the vault's Account URL page. The token tells us which vault you mean.

curl -H "Authorization: Bearer $ENVVAULT_TOKEN" \
  https://mvault.net/v1/api/production-api

Always send the token in the Authorization header. Requests that put a token in the path or query string are refused with 400 token_in_url, because URLs end up in access logs, browser history, proxies and Referer headers. If that happens, revoke the token. GET /v1/api/ lists the secret names (metadata only).

Command line

make build writes the client to bin/envvault. It needs a token and the key you saved when the file was encrypted. ENVVAULT_URL defaults to https://mvault.net.

export ENVVAULT_TOKEN=mvt_...
export ENVVAULT_KEY=...

envvault pull --secret production-api -o .env
envvault run --secret production-api -- ./server

pull writes the file mode 0600 and refuses to overwrite an existing file unless you pass --force. run starts the command with those variables in its environment, and strips ENVVAULT_TOKEN and ENVVAULT_KEY so the child process does not inherit them.

The token and the key can come from mode-0600 files instead of the environment: --token-file and --key-file. Older per-secret evm_ tokens still work with --team and --store against /api/v1/teams/{team}/stores/{store}/envelope.

From a Go program

There is no client library to import. Call the account URL, then open the envelope with the standard library. The key is 32 bytes, encoded as base64url without padding. The response header X-Envvault-Team-ID is the team id inside the authenticated data.

req, err := http.NewRequest(http.MethodGet,
    "https://mvault.net/v1/api/"+secret, nil)
req.Header.Set("Authorization", "Bearer "+token)
req.Header.Set("Accept", "application/json")
resp, err := http.DefaultClient.Do(req)
teamID := resp.Header.Get("X-Envvault-Team-ID")

The body is JSON: v is 1, alg is AES-256-GCM, and iv and ciphertext are base64url. Reject the envelope unless aad is exactly envvault:v1: plus the team id, a colon, and the secret name. Decode the key, the IV and the ciphertext, then:

block, err := aes.NewCipher(rawKey)
gcm, err := cipher.NewGCM(block)
plain, err := gcm.Open(nil, iv, ciphertext, []byte(env.AAD))

The plaintext is the .env file. Keep the key in the process that decrypts, and never send it to EnvVault.