NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3608 most downloaded on npm
a secure dotenv–from the creator of `dotenv`
Last release 3 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
358 releases · first in 2023
see CHANGELOG
see CHANGELOG
Envfile the filename. Final decision. (#1003)see CHANGELOG
One column per month.
see CHANGELOG
see CHANGELOG
see CHANGELOG
? Choose private key custody …
❯ ⛉ Local
⛨ Dotenvx Armor
⛊ Password Managers
see CHANGELOG
see CHANGELOG
Envfile renamed to Envspec file (#996)dotenvx init removed. renamed to dotenvx spec. (#996)see CHANGELOG
see CHANGELOG
armor up should read for os secret store, 1password, and bitwarden (#992)see CHANGELOG
see CHANGELOG
dotenvx feedback command so you (and your coding agent) can give feedback on the cli (#987)dotenvx init for generating your Envfile (#990)import { config } from '@dotenvx/dotenvx', broken in 2.30.0 by the withEvents export (#989).dotenvx validate renamed to dotenvx check and works off Envfile only going forward. Support for .env.example dropped. Switch to using an Envfile.dotenvx define removed. Use dotenvx init.see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx protect to prevent plaintext .env files from being committed to code on a machine (#980)dotenvx gitignore. Use dotenvx protect.dotenvx precommit. Use dotenvx protect.dotenvx prebuild. Use dotenvx protect --docker.see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
Your private key
├── ⛉ Local Custody
│ ├── OS (macOS Keychain / Windows Credential Manager / Linux Secret Service)
│ ├── 1Password
│ ├── Bitwarden
│ └── File (.env.keys)
└── ⛊ Managed Custody
└── ⛨ Armor
see CHANGELOG
see CHANGELOG
run --validate flag and validate command against .env.example file. To be replaced soon with a modern validation scheme.see CHANGELOG
see CHANGELOG
dotenvx 1password up|down|push|pull and dotenvx bitwarden up|down|push|pull (#969)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
.env.keys by default (#967)see CHANGELOG
see CHANGELOG
see CHANGELOG
-p shorthand for --plain; use --plain insteadsee CHANGELOG
see CHANGELOG
-f and the config({ path }) option. Example: dotenvx run -f .env.local,.env -- node index.jsDOTENV_PATH (or DOTENV_F) to support the same. Example: DOTENV_PATH=.env.local,.envDOTENV_CONFIG_* variables to DOTENV_CONVENTION, DOTENV_IGNORE, and DOTENV_QUIET, while retaining their existing DOTENV_CONFIG_* names as fallbackssee CHANGELOG
see CHANGELOG
~/.local/bin when /usr/local/bin is not writable (#955)see CHANGELOG
see CHANGELOG
dotenvx enc and dotenvx dec shorthands for encrypt and decrypt (#943)dx alias for shorter dx run --, dx enc, etc (#944)path (#942)see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx del command for deleting a key from a .env file (#939).env.vault from precommit/prebuild sealed checks (vault-format ciphertext is already safe to commit)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx armor open to open armored key details in browser (#930)see CHANGELOG
see CHANGELOG
encrypted: value (#927)see CHANGELOG
see CHANGELOG
dotenvx curl. Allows you to control your Dotenvx Armor account directly from your agent inside Codex, Claude, etc. (#923)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
.env.example in subdirectories from precommit (#920)see CHANGELOG
see CHANGELOG
DOTENV_CONFIG_IGNORE global convenience (#919)see CHANGELOG
see CHANGELOG
see CHANGELOG
bw:// secrets in your .env files. (#915)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
-ek and -ik to dotenvx get (#913)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
op:// secrets in your .env files. (#908)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
'Let\'s go' now correctly escapes to Let's go (#903)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx update (#897)injected env to stderr instead of stdout. This makes it more reliable to do things like piping output to a file without needing --quiet. (#898)see CHANGELOG
see CHANGELOG
run --redact to keep secrets out of command output. (#894)see CHANGELOG
see CHANGELOG
ls from @dotenvx/dotenvx is now async/await. (#893)see CHANGELOG
see CHANGELOG
see CHANGELOG
--quiet should not display the spinner and its stderr messages (#889)see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx armor login attempts to set the DOTENVX_ARMOR_TOKEN in your native OS secret store going forward. For current Armor users run dotenvx armor logout and then dotenvx armor login to make use of this immediately. (#886)see CHANGELOG
see CHANGELOG
--mask on get, run, decrypt (#885)see CHANGELOG
see CHANGELOG
native up|down|pull|push for windows (#884)see CHANGELOG
see CHANGELOG
native up|down|pull|push for windows (#883)see CHANGELOG
see CHANGELOG
config(path:) as a directory like app/web. Useful for monorepos (#882)see CHANGELOG
see CHANGELOG
see CHANGELOG
@dotenvx/tooling (#879)see CHANGELOG
see CHANGELOG
dotenv and commander for @dotenvx/tooling (#878)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
lock up and lock down commands for password protecting private keys (#875)keychain commands to native to make way for windows and linux. (#875)--no-ops. Use --no-armor. (#875)Your coding agent can read these notes before it upgrades. Set up the MCP server →