Encryption

Require encrypted values in your environment sources.

Usage

encrypted: true is the default. It requires an encrypted source for a nonblank value. Use encrypted: false for values that may remain plaintext. encrypt is an alias.

strict true

env "API_KEY"
env "PORT", type: "port", encrypted: false

Declaring a rule does not rewrite your .env; run dotenvx encrypt to encrypt its values. Encryption and redaction are independent: allowing plaintext does not automatically allow output visibility.

Undeclared loaded variables are not an allowlist violation. They still use the default encryption policy. Dotenvx public-key metadata is exempt from the encryption requirement.