Zero-knowledge .env storage

Your .env, encrypted before it leaves your browser.

EnvVault keeps your team's environment files in one place without ever being able to read them. You hold the key. We hold ciphertext.

AES-256-GCM · WebCrypto · ciphertext only

what EnvVault stores Encrypted
{
  "v": 1,
  "alg": "AES-256-GCM",
  "iv": "q3N0dGVudC1pdi0x",
  "ciphertext": "Zk9xL2h3c1N2Y3Rz…",
  "aad": "envvault:v1:team:production"
}
That is the whole record. No key, no plaintext, nothing we could hand over.

How it works

Three steps, and the key never travels.

  1. 1

    Paste and encrypt

    Paste your .env. Your browser encrypts it with a key it generates on the spot.

  2. 2

    Save your key

    The key is shown once, in your browser. Keep it in your password manager. We never see it.

  3. 3

    Pull it anywhere

    Open it in the browser or pull it on a server with the CLI. Decryption always happens on your side.

What EnvVault can and cannot see

What we store

  • The encrypted envelope
  • The secret's name and label
  • Who can access it, and an audit trail of access

What we never see

  • Your decryption key, not even for a moment
  • Your plaintext .env values
  • A way to recover a lost key, because there isn't one

Built for small teams

Everything you need, nothing you have to trust us with.

Labels

Tag each secret Development, Staging, Production or anything you like.

Version history

Every save is a new encrypted version. Roll back in one click.

People

Invite colleagues to the vault. Hand them keys through a channel you trust.

Audit log

See who created, changed and fetched what, and when.

Free to start.

Sign in with Google and create your first encrypted .env in under a minute.