Skip to content

CLI Reference

Global Flags

Flag Env Var Default Description
--config ANZEN_CONFIG Override .anzen.toml path
--project ANZEN_PROJECT Override project path
-e, --env ANZEN_ENV default Environment to use
-g, --group ANZEN_GROUPS Groups to load (repeatable)
--log-level ANZEN_LOG_LEVEL Log level: trace, debug, info, warn, error
-n, --dry-run ANZEN_DRY_RUN false Simulate operations without making any changes

All flags can be set via environment variables with the ANZEN_ prefix.

Commands

anzen init

Creates a .anzen.toml from a sample template in the current directory (or path specified by --config).

anzen init
anzen --config path/to/.anzen.toml init

anzen trust

Trusts the current project's configuration. Computes a SHA-256 hash of the config file and stores it in the global state. Prompts for:

  1. Confirmation that the config file is safe
  2. Provider selection (project default, global alias, or raw URI)
  3. Whether to allow secret generation

If the project was previously trusted, offers to just update the hash or fully reconfigure.

anzen distrust

Removes the current project from the trust database.

anzen get <SECRET_NAME>

Retrieves and prints a single secret's resolved value to stdout (no trailing newline).

anzen get DATABASE_URL
anzen -e prod get DATABASE_URL

anzen set <KEY>

Stores a secret value in the provider. The value is read from an interactive password prompt. If stdin is a pipe, reads from stdin instead.

anzen set API_KEY
echo "secret-value" | anzen set API_KEY
anzen -e prod set API_KEY

Flags:

Flag Description
--stdin Read value from stdin (auto-detected for pipes)

anzen run [flags] -- <command>

Resolves secrets for the active environment/groups and executes the command with them injected as environment variables.

anzen run -- go test ./...
anzen -e test -g database run -- go test ./...
anzen -e dev run -s 'echo $VARIABLE'

Flags:

Flag Description
-s, --shell Wrap command in sh -c (enables shell expansion)

anzen export

Prints resolved secrets as KEY=VALUE pairs to stdout.

anzen export
anzen export --shell
anzen -e prod -g web export --shell

Flags:

Flag Description
--shell Prefix each line with export and quote values

Useful with eval:

eval "$(anzen export --shell)"

anzen generate [SECRET_NAME...]

Generates secrets that have a generate block in their definition. By default, only generates secrets not yet present in the provider.

anzen generate SECRET_KEY
anzen generate --all
anzen generate --all --no-fetch

Flags:

Flag Description
--all Generate all generatable secrets
--no-fetch Skip checking provider for existing values
--insecure-allow-generation Skip confirmation prompt (for CI/automation)

anzen copy [secrets...]

Copies secrets between providers. If no secret names are given, copies all secrets defined in the current environment.

anzen copy --from os-keychain:// --to gopass://
anzen copy --from project --to gopass:// API_KEY DATABASE_URL

Flags:

Flag Required Description
--from yes Source provider URI or project
--to yes Destination provider URI

Using project as a provider value resolves to the project's configured provider.

anzen status

Shows current session info, project trust state, and provider status.

anzen summary

Displays the full project configuration: variables, environments, groups, and their properties.

anzen validate

Validates global config, global state, and the project config file. Exits non-zero on parse errors.