Get started

Configure environment variables

Sign in to Infisical, bind a workspace, and run commands with injected variables.

6 min readUpdated 3 days agoEdit on GitHub

Infisical stores the values; one.manifest.json records the binding and variable names. One CLI injects variables when commands run, without an intermediate .env file.

1. Sign in

one login
one whoami

The browser session is stored in the system keyring. New workspaces can be created and run without a binding; sign in when managed variables are needed.

2. Set a variable

From a workspace containing a project named api:

one env set DATABASE_URL -p api --env dev

The terminal asks for the value with hidden input. The first env operation initializes the Infisical project binding if absent. To use an existing project, select it in Dashboard workspace settings before running the command.

At the workspace root, omit -p for shared values; interactive set offers a scope selector. For scripts, pass a value explicitly and use --yes to confirm changes.

3. Inspect names

one env list -p api --env dev

list shows names only. The CLI does not print secret values; use one exec to inject them into commands.

4. Run the project

one exec -p api --env dev -- go run ./cmd/server
one run dev --env dev

The binding enables Infisical injection. Unbound projects inherit the shell environment. A configured project's authentication or fetch failure stops execution; local files are not used as a fallback.

Next: environments and folder inheritance, command reference, and migration for older manifests.