Manage every project's .env files and your global shell config from Raycast. Local-only, free, keyboard-first.
The name comes from "butler": your
.envfiles belong to you. The extension fetches, registers and guards them. Your project.envfiles stay the source of truth; Env Keeper only keeps local plaintext history copies (snapshots and presets) on your machine — see Security boundaries.
.env files are scattered across projects, and global environment variables hide in ~/.zshrc. To find which project uses a given key, temporarily disable a variable, or generate a .env.example for your team, you end up opening files by hand. Env Keeper puts all of that into one keyboard-driven panel.
••••••••; reveal with one shortcut. Copying a secret keeps it out of clipboard history..env even though it never enters git; roll back anytime..env.example in one step — generated as a merge, so hand-written notes in the template survive.| Command | What it does |
|---|---|
| Manage Envs | Projects: register a project, manage variables per environment, snapshots and restore, generate .env.example.Shell: manage global variables / aliases / snippets and generate ~/.env-keeper/shell.sh. |
| Search Env Vars | Search variable names or values across all projects, profiles and the shell config. |
| Jump to | Open a project, env file, profile or shell snippet by name; snippets can be toggled in place. |
Project environments are edited directly in the .env files under the project directory. The live values are never moved elsewhere, so the extension coexists naturally with git, teammates, Vite and Docker.
Alongside that, Env Keeper keeps local history copies for rollback and reuse (details in Security boundaries): automatic snapshots of each .env file, and presets you save. These are extra copies of your environment content, not a replacement for the files.
The file's fingerprint is recorded on open and checked again before save: if something else changed the file in between, you get to decide instead of a silent overwrite.
Everything the extension owns lives in ~/.env-keeper/, fully transparent:
~/.env-keeper/
├── registry.json # registered projects
├── presets.json # saved presets (full env content, plaintext)
├── shell.json # shell snippets
├── shell.sh # generated from shell.json, sourced by .zshrc
├── snapshots/ # history of each project's .env files (full contents, plaintext)
├── config-history/ # history of the config files above, including presets.json
└── backups/ # backups taken before touching .zshrc
Moving to a new machine = copying this directory. Note that it holds plaintext secrets (see below), so transfer it over a channel you trust.
Local plaintext copies of your environment content. Your project .env files remain the source of truth, but Env Keeper also stores copies for history and reuse:
.env file;~/.env-keeper/presets.json, and earlier versions of that file are kept in config-history/.These copies are plain text and may contain secrets, including values that have since been removed or rotated in the original file. If you no longer want old values retained, delete the snapshot history and the presets (and their history) from inside the extension, or delete the matching files under ~/.env-keeper/. Keep the directory out of git, cloud sync and backups you don't trust.
Masking affects display only. .env and shell.sh must stay in plain text or your programs and shell can't read them. It protects against someone glancing at your screen, not against the file being read.
The extension does not encrypt. For encryption use dotenvx; Env Keeper recognizes the encrypted: prefix and stops you from editing those values by accident.
The extension never reads or modifies .envrc. If one is present, it only tells you that direnv is in play.
~/.zshrc and ~/.bash_profile)..env are parsed the same way dotenv does, so the value shown in the UI equals the value your program gets.