Encryption
Require encrypted values in your environment sources.
Usage
encrypted: true is the default. It requires an encrypted source for a nonblank value. Use encrypted: false for values that may remain plaintext. encrypt is an alias.
strict true
env "API_KEY"
env "PORT", type: "port", encrypted: false
Declaring a rule does not rewrite your .env; run dotenvx encrypt to encrypt its values. Encryption and redaction are independent: allowing plaintext does not automatically allow output visibility.
Undeclared loaded variables are not an allowlist violation. They still use the default encryption policy. Dotenvx public-key metadata is exempt from the encryption requirement.
Related