Armor
Manage private-key custody with Dotenvx Armor.
Keep your encrypted .env in your project. Let Armor manage access to its private key.
Store
Start with an encrypted .env. Sign in, then move its private key into Armor:
$ dotenvx armor login
$ dotenvx armor up
Dotenvx removes the local key after Armor accepts it. Your .env stays encrypted.
For a specific environment, use dotenvx armor up -f .env.production.
Run
$ dotenvx run -- node index.js
Dotenvx requests the key from Armor before starting your app. Sign in on each machine that needs access. If approval is required, approve the request in Armor.
Move back
Move the private key back into .env.keys:
$ dotenvx armor down
Keep .env.keys out of source control.
See Armor commands for teams, tokens, and other options.