.env.keys

Keep your private keys in a local .env.keys file.

Keep the encrypted .env in your project. Keep the private key in .env.keys.

Store

Encrypt your .env:

$ dotenvx encrypt

Choose Local, then File .env.keys. Dotenvx saves the private key alongside your encrypted .env.

Add .env.keys to .gitignore. Commit .env, but keep .env.keys private and backed up.

Run

Dotenvx reads .env.keys automatically.

$ dotenvx run -- node index.js

Replace node index.js with your app's command.

Other environments

For .env.production, use:

$ dotenvx encrypt -f .env.production
$ dotenvx run -f .env.production -- node index.js

The key is named DOTENV_PRIVATE_KEY_PRODUCTION. See the file format for more.