Armor

Manage private-key custody with Dotenvx Armor.

Keep your encrypted .env in your project. Let Armor manage access to its private key.

Store

Start with an encrypted .env. Sign in, then move its private key into Armor:

$ dotenvx armor login
$ dotenvx armor up

Dotenvx removes the local key after Armor accepts it. Your .env stays encrypted.

For a specific environment, use dotenvx armor up -f .env.production.

Run

$ dotenvx run -- node index.js

Dotenvx requests the key from Armor before starting your app. Sign in on each machine that needs access. If approval is required, approve the request in Armor.

Move back

Move the private key back into .env.keys:

$ dotenvx armor down

Keep .env.keys out of source control.

See Armor commands for teams, tokens, and other options.