NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #3608 most downloaded on npm
a secure dotenv–from the creator of `dotenv`
Last release 3 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 9 days
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
358 releases · first in 2023
see CHANGELOG
see CHANGELOG
.env1 (.env*) file format. (private key expands to DOTENV_PRIVATE_KEY_DEVELOPMENT1) (#312)see CHANGELOG
One column per month.
dotenvx decrypt command. works inversely to dotenvx encrypt. same flags. (#294)--stdout option to dotenvx decrypt. example: dotenvx decrypt -f .env.production --stdout > somefile.txt (#298)--stdout option to dotenvx encrypt. example: dotenvx encrypt -f .env.production --stdout > somefile.txt (#298)secrets.txt it can still decrypt from DOTENV_PRIVATE_KEY by seeking out the invert of the DOTENV_PUBLIC_KEY inside secrets.txt (#302)dotenvx convert - still at dotenvx encryptdotenvx vault - still at dotenvx ext vaultsee CHANGELOG
see CHANGELOG
set. example: dotenvx set KEY -- "- + * ÷" (#293)@inquirer/confirm and ora (#285)dotenvx ext hub, replace with dotenvx-ext-hub (install there to continue using hub) (#291)see CHANGELOG
see CHANGELOG
see CHANGELOG
prepare and postinstall scripts and replace with npm run patch for development and binary building (#286)see CHANGELOG
see CHANGELOG
--key option - dotenvx encrypt -k HELLO (#281)see CHANGELOG
see CHANGELOG
dotenvx invocations - dotenvx run -- dotenvx run -- env (#279)glob with faster approach (#278)see CHANGELOG
see CHANGELOG
see CHANGELOG
process.env and/or with --overload (#271)see CHANGELOG
see CHANGELOG
🎉 dotenvx has made it to 1.0.0. There are BREAKING CHANGES ⚠️ .
dotenvx set KEY value --plain to set plain text valuesdotenvx ext 🔌 as a location to place extensions like gititgnore, precommit, ls, and more. better than cluttering up core features like run, get/set, and encrypt.dotenvx pro 🏆 command with coming soon and link to GitHub issue (if you wish to be notified of progress. will provide tooling/features for teams)BREAKING ⚠️
dotenvx set (use dotenvx set KEY value --plain to set plain values)dotenvx encrypt to dotenvx ext vault encrypt (for managing .env.vault files)dotenvx convert to dotenvx encryptls to dotenvx ext lsgenexample to dotenvx ext genexamplegitignore to dotenvx ext gitignoreprebuild to dotenvx ext prebuildprecommit to dotenvx ext precommitscan to dotenvx ext scanhub to dotenvx ext hubvault to dotenvx ext vaultsettings to dotenvx ext settings(for many of these moved commands, for example dotenvx genexample, still work in 1.0.0 but with a large deprecated notice - DEPRECATION NOTICE: [genexample] has moved to [dotenvx ext genexample]. Please change your muscle memory to dotenvx ext genexample, as these deprecated command paths will be removed in a later minor version. importantly dotenvx encrypt was not able to be preserved because as it is now in use for encrypted .env files rather than .env.vault files)
This is a BIG release that sets the tone for dotenvx's core offering and features while maintaining room for growth. Thank you everyone for your support and usage of dotenvx 🙏.
blog post: "From dotenv to dotenvx: Next Generation Config Management"
see CHANGELOG
see CHANGELOG
dotenvx vault convert to dotenvx vault migrate (#251)install.sh regex version check to be sh compatible (not just bash)see CHANGELOG
see CHANGELOG
see CHANGELOG
.github folder from published binaries on npm (example: npm code)install.shsee CHANGELOG
see CHANGELOG
install.sh along with sanity checks (#250)see CHANGELOG
see CHANGELOG
CHANGELOG.md in npm releaseinstall.sh in package releasesee CHANGELOG
see CHANGELOG
package.json to match project's license BSD-3.see CHANGELOG
see CHANGELOG
dotenvx set HELLO '' --encrypt (#236)see CHANGELOG
see CHANGELOG
options.debug, options.verbose, options.quiet, and options.logLevel to .config() (#233)see CHANGELOG
see CHANGELOG
replace when replacing double, single, or backticked quoted at anywhere in the .env file. (#232)see CHANGELOG
see CHANGELOG
replace function regex - to handle more edge case scenarios with replacing KEY/values (#227)see CHANGELOG
see CHANGELOG
require('@dotenvx/dotenvx').config() for DOTENV_PRIVATE_KEY decryption (#225)see CHANGELOG
see CHANGELOG
.env.vault deprecated warning when using DOTENV_KEY. Provide instructions to convert to encrypted .env files. (#224)see CHANGELOG
see CHANGELOG
vault convert command to list convert instructions for converting .env.vault to encrypted .env files (#222)To convert your .env.vault file to encrypted .env file(s):
1. Run [dotenvx vault decrypt]
2. Run [ls -a .env*]
Lastly, convert each .env(.environment) file:
3. Run [dotenvx convert -f .env.production]
For example:
$ dotenvx convert -f .env
$ dotenvx convert -f .env.ci
$ dotenvx convert -f .env.production
Afterward:
Update production with your new DOTENV_PRIVATE_KEY_PRODUCTION located in .env.keys
Learn more at [https://dotenvx.com/docs/quickstart#add-encryption]
encryptme to convert (#222)see CHANGELOG
see CHANGELOG
dotenvx encryptme command to convert an entire .env file to an encrypted .env file. (#213)precommit smart enough to check if a .env* file is encrypted or not. If fully encrypted, then allow precommit check to pass (#211)see CHANGELOG
see CHANGELOG
--convention flag to getsee CHANGELOG
see CHANGELOG
dotenvx encrypt => dotenvx vault encryptdotenvx decrypt => dotenvx vault decryptdotenvx status => dotenvx vault statushub commands are being completely deprecated (they will be fully removed in upcoming 1.0.0 release). We will provide .env.keys tooling at a later time (replacing hub) but in the context of the new --encrypt flag functionality below.env files with a single command. Pass the --encrypt flag. 🎉$ dotenvx set HELLO World --encrypt
set HELLO with encryption (.env)
A
DOTENV_PUBLIC_KEY(encryption key) and aDOTENV_PRIVATE_KEY(decryption key) is generated using the same public-key cryptography as Bitcoin.
Further notes:
DOTENV_PUBLIC_KEY lives in the .env file. You can safely share this with whomever you wish.DOTENV_PRIVATE_KEY lives in your .env.keys file. Share this only with those you trust to decrypt your secrets..env files like this it is safe to commit them to source code. This makes reviewing PRs that contain secrets much easier.dotenvx set HELLO world --encrypt.DOTENV_PRIVATE_KEY on your server to decrypt these values using dotenvx run -- yourcommanddotenvx set HELLO production -f .env.production --encrypt (for example).env.keys, but until then safely share with team members you trust..env files. It has many benefits over .env.vault files. We will be sunsetting the .env.vault mechanism but its tooling will stay around in dotenvx for at least 1 year to come - under dotenvx vault parent command..env files.see CHANGELOG
see CHANGELOG
dotenvx status against any untracked (not in .env.vault) files (#196)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
1 if get KEY not found/undefined (#185)see CHANGELOG
see CHANGELOG
set command, and optionally pass --env-file flag(s) to set usage: dotenvx set HELLO World (#182)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
.env.something.something (useful for Next.js pattern of .env.development.local) (#174)see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
see CHANGELOG
hub open and hub push (#169)see CHANGELOG
see CHANGELOG
see CHANGELOG
dotenvx get --quiet will display the value no matter what (adds a blank0 logger level) (#161)dotenvx get to use run under the hoodsee CHANGELOG
see CHANGELOG
see CHANGELOG
DOTENV_KEY is present and --env-file flag is set. assume to still look for .env.vault file as first in line (#157)see CHANGELOG
see CHANGELOG
--env-vault-file, --env-file and --env flags (for example: dotenvx run --env "HELLO=one" --env-file=.env will prioritize --env flag. Add --overload here to prioritize --env-file or reverse the order.). you can now mix and match multiple flags in any complex order you wish and dotenvx will respect it. (#155)see CHANGELOG
see CHANGELOG
dotenvx settings command to list your current settings. in the future we'll provide ways to modify these settings as dotenvx's functionality grows (#153)see CHANGELOG
see CHANGELOG
dotenvx.exe is functional immediately after release (#141)see CHANGELOG
see CHANGELOG
.zip download option for windows executable (#140)got from top level deps (#139)see CHANGELOG
see CHANGELOG
see CHANGELOG
hub pull command to pull a repo's .env.keys down. (#129)see CHANGELOG
see CHANGELOG
process.env. evaluate only what's set in a .env* file (#125)see CHANGELOG
see CHANGELOG
hub push with [directory] option. use for monorepos. for example: dotenvx hub push apps/backend (#121)see CHANGELOG
see CHANGELOG
DATABASE_URL="postgres://$(whoami)@localhost/my_database" (#113)see CHANGELOG
see CHANGELOG
# personal.dotenvx.com will be considered personal and will not be encrypted to .env.vault (#110)see CHANGELOG
see CHANGELOG
require('@dotenvx/dotenvx').config() expands/interpolates variables. this matches the behavior of run. (note that this behavior differs from the original require('dotenv').config() (#107)see CHANGELOG
see CHANGELOG
genexample function on lib/main.js for export convenience (#102)which npm module to find system command path for user inputted command(s) (#105)main.inject function (#102)see CHANGELOG
see CHANGELOG
--env flag on the .env.vault decryption portion of run (#101)see CHANGELOG
see CHANGELOG
see CHANGELOG
--env flag. for example, dotenvx --env="HELLO=World" -- yourcommand (#94)see CHANGELOG
see CHANGELOG
see CHANGELOG
scan command to scan for possible leaked secrets in your code (#90)Your coding agent can read these notes before it upgrades. Set up the MCP server →