Agents, meet Envfile.
The Problem
We created dotenv to make configuration simple. A small file became part of how the world builds software. Now you're building with it too.
You've done your best to handle secrets responsibly. But you're nondeterministic. Sometimes you screw up. A credential lands in a log. A secret ends up in generated code.
You've been reaching for encrypted .env files. That's a big step. But you need more. Which variables are required? What's valid? How should each secret be handled? You need rules that Dotenvx can enforce.
Introducing Envfile.
Envfile
# Envfile
strict true
# Check the port.
env "PORT", type: "port", encrypted: false, redacted: false
# Limit the environment to known values.
env "NODE_ENV", enum: ["development", "test", "production"]
# Keep secrets encrypted and out of output.
env "DATABASE_URL", type: "url", encrypted: true, redacted: true
# Use a secret through a proxy.
env "STRIPE_SECRET_KEY", proxy: { domain: "api.stripe.com" }
- Safe to commit.
- Keys and instructions, not keys and values.
- Dotenvx enforces the rules.
Redaction
Envfile keeps secrets out of terminal output automatically. Your app gets the real values; logs show [REDACTED].
# Envfile
strict true
env "DATABASE_URL"
$ dotenvx run -- printenv DATABASE_URL
[REDACTED]
Strictness
With strict true, invalid configuration stops your command before it starts. Your coding agent or process gets an error instead.
# Envfile
strict true
env "API_KEY"
$ dotenvx run -- node index.js
☠ [INVALID_ENV] API_KEY is required
$ echo $?
1
Encryption
Secrets must be encrypted by default. If plaintext slips into your .env file, Envfile stops your app from starting.
# Envfile
strict true
env "API_KEY"
$ dotenvx run -- node index.js
☠ [INVALID_ENV] API_KEY is not encrypted
Types
Catch bad configuration before your app does. Validate ports, URLs, emails, and more.
# Envfile
strict true
env "PORT", type: "port", encrypted: false
$ dotenvx run -- node index.js
☠ [INVALID_ENV] PORT must be at most 65535
Protect
Keep plaintext secrets out of commits. dotenvx protect blocks Git from staging files that break your Envfile’s encryption rules.
# Envfile
strict true
env "API_KEY"
$ dotenvx protect
⛉ protection: full (.env*, .env.keys*)
$ echo 'API_KEY=example-only' > .env
$ git add .env
☠ [PLAINTEXT_ENV] API_KEY not encrypted (".env"). fix: run [dotenvx encrypt -f .env]
fatal: .env: clean filter 'dotenvx.protect' failed
Fine-Tune
Choose the rules for each variable. Allow plaintext for a port. Show public values in logs. Keep secrets locked down.
env "PORT", type: "port", encrypted: false, redacted: false
Generate
Start with the .env files you already have. Generate your Envfile in one command.
dotenvx spec