Skip to main content

Load your encrypted environment when your Python app starts, decrypted on the machine that runs it.

Website • Dashboard • Documentation • Services Status


Envless runtime for Python

envless-env fetches your environment from Envless when your app starts, decrypts it on the machine that runs it, and hands it to your code typed. It is the Python twin of @goenvless/env: the same loader, the same cache, the same rules for the process environment and the same errors. A parity check in the Envless repository replays the same scenarios against both packages before each release.

It runs on Python 3.10 and newer, and depends on envless-sdk for the HTTP client and the crypto, plus anyio.

Installing

pip install envless-env

Or uv add envless-env, or poetry add envless-env. The package installs as envless-env and imports as envless_env.

Loading at boot

Import envless_env.register before anything reads a variable. It fetches, decrypts and fills os.environ with every name that is safe to set, and raises if it cannot.

import envless_env.register  # noqa: F401
from envless_env.server import env

database_url = env.DATABASE_URL

Set ENVLESS_TOKEN to a machine key (ev_sk_…) and ENVLESS_KEY or ENVLESS_PASSPHRASE to decrypt. The project and environment come from ENVLESS_PROJECT and ENVLESS_ENV, or from the .envless file that envless link writes. Under envless run none of that is needed: the values are already in the environment and nothing is fetched.

Reading

from envless_env.server import env, optional

port = env.PORT
sentry_dsn = optional.SENTRY_DSN

env.NAME is coerced to the type you set in Envless: a whole number comes back as an int and a fractional one as a float, a boolean is True only for true or 1, and everything else is a str. A name that is not set raises MissingVariableError, and optional returns None instead. envless_env.client.env sees only the variables marked client, for anything you hand to a browser or a template.

python -m envless_env types writes envless_env_types.py, the same views typed by name from your variables in Envless, so mypy and pyright catch a misspelt name or a server variable read on the client.

The env objects refuse to be pickled, iterated or printed with their values, so a stray repr() in a log line or a debug page shows a count, never a secret. load() returns a plain dict you own when you need every value at once.

Frameworks

from fastapi import FastAPI

from envless_env.fastapi import lifespan

app = FastAPI(lifespan=lifespan)

envless_env.django.context_processor hands client variables to Django templates, envless_env.flask.init_app loads into a Flask app's config, and envless_env.pydantic.EnvlessSettingsSource feeds pydantic-settings. For serverless functions, envless_env.edge.load takes every input as an argument and touches nothing on disk.

The rest, the cache, the server and client split, every framework recipe and every export, lives in the documentation.

Metadata

Release files for envless-env 0.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for envless-env 0.0.1
File Size Uploaded
envless_env-0.0.1.tar.gz 21.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for envless-env 0.0.1
File Interpreter ABI Platform
envless_env-0.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 57.9 kB

Release files / envless_env-0.0.1.tar.gz

Download URL envless_env-0.0.1.tar.gz
Size 21.2 kB
Tags Source
SHA-256 checksum
How to use checksums
52649ce509f8a685ce6c95b6a45786f7efd5215e00dc0dfced6f553d326cbb3f
BLAKE2b-256 checksum
How to use checksums
e6f85a59c8c7061ec56f3829cfc0b9c89aff7fab38a2e17e7a8174ebb333a5b2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / envless_env-0.0.1-py3-none-any.whl

Download URL envless_env-0.0.1-py3-none-any.whl
Size 36.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d5a6669d50f9664fdcd19916bee7cd2c31843940dc6e3bb72aae26e5df6fdc61
BLAKE2b-256 checksum
How to use checksums
cd245ddabaa628bd0040c929ec61976aa738e54d56a4a5d1bd768e896db40d2b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.0.1 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page