dotenvx-secrets
dotenvx secrets
dotenvx is a drop-in dotenv replacement (BSD-3-Clause, dotenvx/dotenvx) that
injects .env values into a child process, encrypts .env files with secp256k1
keypairs, resolves vault references, and can redact secret values from the child's
output stream.
Its agent-relevant capability is dotenvx run --redact -- <agent>: the agent gets
the real credentials, but any occurrence of those literal values in its stdout/stderr
is replaced with [REDACTED] before reaching the terminal or transcript.
Read this first: --redact is not a security boundary
Redaction is best-effort exact literal substring matching on the child process's
piped stdout and stderr. src/lib/helpers/redactOutput.js does
result.split(sensitiveValue).join('[REDACTED]') — no regex, no case-insensitivity,
no encoding awareness. It therefore does not catch: