OSS Tanbou

encrypt .env values for version control and decrypt them into environment variables at runtime

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
5,821
Primary language
JavaScript
License
BSD-3-Clause
Repository last updated
Sep 29, 2026
On this page

Overview

dotenvx is a CLI and library for loading .env files while also handling secret encryption, runtime injection, and protection. Encrypted .env files can travel with the code, while the private key is kept separately and used by dotenvx run -- ... to decrypt values before launching a process. It also supports multiple environments and several key-custody options.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Share encrypted .env files through version control

dotenvx encrypt converts values in .env into ciphertext so the encrypted file can be committed and shared. The private key required for decryption is managed separately from that file.

Sources: [2]

Inject environment variables when launching any command

dotenvx run -- <command> loads the selected environment files, decrypts protected values when required, and injects them into the child process. The workflow is not limited to Node.js applications.

Sources: [2]

Best fit

Fits teams that want one workflow for environment files and secret distribution across local, CI, and deployment environments

It is useful when configuration files should be shareable without storing plaintext secrets in the repository, while local development and deployment use the same environment-loading model.

Sources: [2]

Before adoption

Keep private keys out of the same repository as encrypted .env files

Encrypted .env files are only separated from plaintext when the decryption key is stored elsewhere. Committing the private key alongside the encrypted file defeats that boundary, so custody should use a separate mechanism such as an OS secret store or password manager.

Sources: [2][4]

Check CLI renames introduced in the 2.32 line

Version 2.32.0 renamed Envfile to Envspec and removed dotenvx init in favor of dotenvx spec. Existing scripts and documentation should be checked for obsolete command names when moving to v2.32.2.

Sources: [4][5]

Official sources

  1. [1]dotenvx repository(2026-09-30)
  2. [2]dotenvx v2.32.2 README(2026-09-30)
  3. [3]dotenvx v2.32.2 package metadata(2026-09-30)
  4. [4]dotenvx v2.32.2 changelog(2026-09-30)
  5. [5]dotenvx v2.32.2 release(2026-09-30)
  6. [6]dotenvx BSD-3-Clause license(2026-09-30)
Supplemental curator note

Keeping encrypted .env files beside application code can simplify environment distribution, but the security boundary depends on storing private keys separately. Do not place the decryption key in the same repository as the encrypted file.

Try it in 3 steps

  1. 1

    Install dotenvx 2.32.2

    Add the stable version to the project with the release pinned.

    npm install @dotenvx/dotenvx@2.32.2 --save
  2. 2

    Encrypt the .env file

    Convert plaintext values to ciphertext. Keep the private decryption key out of the same repository as the encrypted .env file.

    npx dotenvx encrypt
  3. 3

    Inject variables when launching a command

    Load the environment file at runtime, decrypt protected values when needed, and inject them into the child process.

    npx dotenvx run -- node index.js
Check the official README

Growth

Growth trends · Last 30 days

5,821 Stars

Trend data is still being collected.

Built with

Categories and tags

Categories

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • cli
  • configuration-file
  • curl
  • dotenv
  • dotenvx
  • end-to-end-encryption
  • env
  • environment-variables
  • homebrew
  • secret-management
  • secret-manager
  • secrets
Stars
5,821
Forks
156
Watchers
12
Open issues
6
Owner type
Organization
Primary language
JavaScript
Repository last updated
Sep 29, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?