Credential Manager

Keep your private keys in Windows Credential Manager.

Keep the private key in Windows Credential Manager, under your user account.

Store

Start with an encrypted .env and .env.keys, then move the key:

$ dotenvx native up

Dotenvx verifies the key in Windows Credential Manager before removing it from .env.keys. Your .env stays encrypted.

For .env.production, add -f .env.production.

Run

$ dotenvx run -- node index.js

Dotenvx reads the key from Windows Credential Manager before starting your app. Run under the same user account, with access to the secret store.

Move back

$ dotenvx native down

This moves the key back into .env.keys. Use dotenvx native pull to copy it back while keeping the stored key.

Keep .env.keys out of source control. See native commands for more.