The archive · Developer & Business Tools · Product decision · 2017–2025
EnvKey's zero-trust bet: open-source v2 in 2022, Cloud wound down by 2025
YC W18 secrets manager bets devs accept UX costs so no host ever sees plaintext; v2 goes MIT open source in 2022, but Cloud shuts down in 2025
EnvKey
What the business is
EnvKey is an end-to-end encrypted configuration and secrets manager: it stores an organization's API keys, encryption keys, credentials and config, pushes them to servers, scripts and tests through a CLI (envkey-source), and sells managed Cloud and Enterprise Self-Hosted tiers.
How it started
The founder (danenania) posted the first version of EnvKey to Hacker News in 2017 and went through Y Combinator's W18 batch. By 2022 EnvKey was an end-to-end encrypted config and secrets manager protecting API keys, credentials and config across servers, scripts and tests, with a spreadsheet-like UI plus a developer CLI that runs any program with the latest environment variables.
What happened
The v2 release on 2022-03-30 made the core fully open source (MIT) and self-hostable, added device-based authorization with a free Cloud tier (20 user devices, 40 server keys), and sold commercial Cloud and Enterprise Self-Hosted tiers. In the thread the founder argued against UX-first cloud rivals like Doppler and host-trusted tools like HashiCorp Vault, citing incidents like Okta; customers pushed back that the v1→v2 migration forced manual key re-imports and that new pricing could multiply a small agency's bill roughly 14x, to which he promised adjustments.
How it ended up
The commercial Cloud was wound down: the GitHub README, still current as of 2026-09-06, announces that as of 2024-08-01 EnvKey Cloud began a six-month wind-down with new registrations disabled and shutdown on 2025-02-01; the MIT-licensed code remains public.
Background
EnvKey is an end-to-end encrypted configuration and secrets manager: it stores API keys, encryption keys, credentials and config, and pushes them to servers, scripts and tests through a CLI, with a spreadsheet-like UI for managing environments.
The founder posted the first version to Hacker News in 2017 and went through Y Combinator's W18 batch. EnvKey's bet was that development teams would adopt environments where even the host never sees plaintext — accepting harder UX in exchange for not trusting any server, cloud provider employee or browser with secrets.
The v2 release on 2022-03-30 open-sourced the core under MIT, made it self-hostable, added device-based authorization with a free Cloud tier, and kept paid Cloud and Enterprise Self-Hosted products. The launch thread drew 225 points and 65 comments, with the founder defending client-side NaCl encryption against convenience-first Doppler and host-trusted Vault while customers complained about migration friction and a possible ~14x price increase.
The ending came later: EnvKey's GitHub README announces that Cloud began a six-month wind-down on 2024-08-01 with new registrations disabled, shutting down on 2025-02-01. The MIT-licensed clients and repository remain public as of 2026-09-06.
What has to be true
- Secret sprawl — keys copied across Slack, .env files and CI — is a real, growing pain every team hits, so the category had demand.
- No host trust and no browser handling were defensible differentiators against UX-first Doppler and host-trusted Vault.
- MIT open-sourcing let skeptical developers audit the encryption before paying, turning the security claim into inspectable evidence.
- Managed Cloud and Enterprise Self-Hosted gave a path from free and open-source adoption to revenue.
What can be applied
A zero-trust promise only compounds if customers can verify it cheaply; open-sourcing the client was the proof, but repricing that punishes small existing teams can hand rivals the migration.
Aftermath
As of 2026-09-06, EnvKey's GitHub README states that EnvKey Cloud began a six-month wind-down on 2024-08-01, disabled new registrations, and shut down on 2025-02-01, with the notice pointing to a detailed wind-down announcement for migration help. The repository and MIT-licensed clients remain public, so the open-source core survives the company.
Sources
spotted an error? The archive wants to know.
Your turn
You just read one. Describe what you are building, and see who is betting on the same thing.
Free account · 3 free questions · no card