env check knows what your app needs from the code and the installed packages — set, sync, and manage secrets from the CLI.
env check cross-references what the code reads and what the installed packages declare against your .env files, and reports each missing variable with how to get its value:
npx mlcl env check
npx mlcl env check --fix # append the fixable ones for younpx mlcl env list --raw # the local .env, unmasked
npx mlcl env set KEY=VALUE # create or update
npx mlcl env get KEY # script-friendly
npx mlcl env unset KEY # comment out; value preservednpx mlcl env push --project <id> # local .env → the project
npx mlcl env pull --project <id> # project → local (write-only secrets skipped)
npx mlcl env detected --project <id> # what the deployed code + packages expectFor secrets you don’t want in files at all, the vault stores them server-side; project API keys (mk_…) authenticate programmatic access:
npx mlcl vault set STRIPE_KEY --project <id> # (also: list / rm / token / broker)
npx mlcl apikey create --project <id> # (also: list / rm)