On this page
Overview
dotenvx is a CLI and library for loading .env files while also handling secret encryption, runtime injection, and protection. Encrypted .env files can travel with the code, while the private key is kept separately and used by dotenvx run -- ... to decrypt values before launching a process. It also supports multiple environments and several key-custody options.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Share encrypted .env files through version control
dotenvx encrypt converts values in .env into ciphertext so the encrypted file can be committed and shared. The private key required for decryption is managed separately from that file.
Sources: [2]
Inject environment variables when launching any command
dotenvx run -- <command> loads the selected environment files, decrypts protected values when required, and injects them into the child process. The workflow is not limited to Node.js applications.
Sources: [2]
Best fit
Fits teams that want one workflow for environment files and secret distribution across local, CI, and deployment environments
It is useful when configuration files should be shareable without storing plaintext secrets in the repository, while local development and deployment use the same environment-loading model.
Sources: [2]
Before adoption
Keep private keys out of the same repository as encrypted .env files
Encrypted .env files are only separated from plaintext when the decryption key is stored elsewhere. Committing the private key alongside the encrypted file defeats that boundary, so custody should use a separate mechanism such as an OS secret store or password manager.
Official sources
- [1]dotenvx repository(2026-09-30)
- [2]dotenvx v2.32.2 README(2026-09-30)
- [3]dotenvx v2.32.2 package metadata(2026-09-30)
- [4]dotenvx v2.32.2 changelog(2026-09-30)
- [5]dotenvx v2.32.2 release(2026-09-30)
- [6]dotenvx BSD-3-Clause license(2026-09-30)
Supplemental curator note
Keeping encrypted .env files beside application code can simplify environment distribution, but the security boundary depends on storing private keys separately. Do not place the decryption key in the same repository as the encrypted file.
Try it in 3 steps
- 1
Install dotenvx 2.32.2
Add the stable version to the project with the release pinned.
npm install @dotenvx/dotenvx@2.32.2 --save - 2
Encrypt the .env file
Convert plaintext values to ciphertext. Keep the private decryption key out of the same repository as the encrypted .env file.
npx dotenvx encrypt - 3
Inject variables when launching a command
Load the environment file at runtime, decrypt protected values when needed, and inject them into the child process.
npx dotenvx run -- node index.js
Growth
Growth trends · Last 30 days
5,821 Stars
Trend data is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- cli
- configuration-file
- curl
- dotenv
- dotenvx
- end-to-end-encryption
- env
- environment-variables
- homebrew
- secret-management
- secret-manager
- secrets
- Stars
- 5,821
- Forks
- 156
- Watchers
- 12
- Open issues
- 6
- Owner type
- Organization
- Primary language
- JavaScript
- License
- BSD-3-Clause
- Repository last updated
- Sep 29, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Express69,502 Stars
2 shared tag(s) · Same language
Build Node.js APIs and web backends by composing routing and middleware into a thin HTTP layer
JavaScript - PLANKA12,592 Stars
2 shared tag(s) · Same language
Share boards, lists, cards, comments, and attachments in a realtime self-hosted Kanban/project tracker
JavaScript - itsnotes34 Stars
2 shared tag(s) · Same language
Combine a Google Keep-style workflow with a two-way Markdown mirror, REST API, MCP, and self-hosted storage
JavaScript - Auth.js28,372 Stars
2 shared tag(s)
Compose OAuth/OIDC, passwordless, WebAuthn, and stateless or database-backed sessions from packages built around standard Web APIs
TypeScript - React250,838 Stars
1 shared tag(s) · 1 shared category(s) · Same language
build web and native interfaces from declarative components
JavaScript - Svelte88,238 Stars
1 shared tag(s) · 1 shared category(s) · Same language
compile components into efficient JavaScript and express reactive UI through runes
JavaScript
Report incorrect information
Tell us if any listing information is incorrect or outdated.