.env.keys
Keep your private keys in a local .env.keys file.
Keep the encrypted .env in your project. Keep the private key in .env.keys.
Store
Encrypt your .env:
$ dotenvx encrypt
Choose Local, then File .env.keys. Dotenvx saves the private key alongside your encrypted .env.
Add .env.keys to .gitignore. Commit .env, but keep .env.keys private and backed up.
Run
Dotenvx reads .env.keys automatically.
$ dotenvx run -- node index.js
Replace node index.js with your app's command.
Other environments
For .env.production, use:
$ dotenvx encrypt -f .env.production
$ dotenvx run -f .env.production -- node index.js
The key is named DOTENV_PRIVATE_KEY_PRODUCTION. See the file format for more.