Dotenv and Dotenvx theme buttons

Agents, meet Envfile.

You know the file. Now know the rules.

The Problem

We created dotenv to make configuration simple. A small file became part of how the world builds software. Now you're building with it too.

You've done your best to handle secrets responsibly. But you're nondeterministic. Sometimes you screw up. A credential lands in a log. A secret ends up in generated code.

You've been reaching for encrypted .env files. That's a big step. But you need more. Which variables are required? What's valid? How should each secret be handled? You need rules that Dotenvx can enforce.

Introducing Envfile.

Envfile

# Envfile
strict true

# Check the port.
env "PORT", type: "port", encrypted: false, redacted: false

# Limit the environment to known values.
env "NODE_ENV", enum: ["development", "test", "production"]

# Keep secrets encrypted and out of output.
env "DATABASE_URL", type: "url", encrypted: true, redacted: true

# Use a secret through a proxy.
env "STRIPE_SECRET_KEY", proxy: { domain: "api.stripe.com" }
  • Safe to commit.
  • Keys and instructions, not keys and values.
  • Dotenvx enforces the rules.

Redaction

Envfile keeps secrets out of terminal output automatically. Your app gets the real values; logs show [REDACTED].

# Envfile
strict true

env "DATABASE_URL"
$ dotenvx run -- printenv DATABASE_URL
[REDACTED]

Strictness

With strict true, invalid configuration stops your command before it starts. Your coding agent or process gets an error instead.

# Envfile
strict true

env "API_KEY"
$ dotenvx run -- node index.js
☠ [INVALID_ENV] API_KEY is required
$ echo $?
1

Encryption

Secrets must be encrypted by default. If plaintext slips into your .env file, Envfile stops your app from starting.

# Envfile
strict true

env "API_KEY"
$ dotenvx run -- node index.js
☠ [INVALID_ENV] API_KEY is not encrypted

Types

Catch bad configuration before your app does. Validate ports, URLs, emails, and more.

# Envfile
strict true

env "PORT", type: "port", encrypted: false
$ dotenvx run -- node index.js
☠ [INVALID_ENV] PORT must be at most 65535

Protect

Keep plaintext secrets out of commits. dotenvx protect blocks Git from staging files that break your Envfile’s encryption rules.

# Envfile
strict true

env "API_KEY"
$ dotenvx protect
⛉ protection: full (.env*, .env.keys*)
$ echo 'API_KEY=example-only' > .env
$ git add .env
☠ [PLAINTEXT_ENV] API_KEY not encrypted (".env"). fix: run [dotenvx encrypt -f .env]
fatal: .env: clean filter 'dotenvx.protect' failed

Fine-Tune

Choose the rules for each variable. Allow plaintext for a port. Show public values in logs. Keep secrets locked down.

env "PORT", type: "port", encrypted: false, redacted: false

Generate

Start with the .env files you already have. Generate your Envfile in one command.

dotenvx spec

Quickstart Spec