Credential Manager
Keep your private keys in Windows Credential Manager.
Keep the private key in Windows Credential Manager, under your user account.
Store
Start with an encrypted .env and .env.keys, then move the key:
$ dotenvx native up
Dotenvx verifies the key in Windows Credential Manager before removing it from .env.keys. Your .env stays encrypted.
For .env.production, add -f .env.production.
Run
$ dotenvx run -- node index.js
Dotenvx reads the key from Windows Credential Manager before starting your app. Run under the same user account, with access to the secret store.
Move back
$ dotenvx native down
This moves the key back into .env.keys. Use dotenvx native pull to copy it back while keeping the stored key.
Keep .env.keys out of source control. See native commands for more.