同步 .env 文件 - 由 `dotenv` 的创建者提供
dotenv-vault is a cli to sync .env files across machines, environments, and team members.
[!NOTE] dotenv-vault is a paid only cloud service for syncing your .env files (as of May 2025).
Looking for a free cloud-less alternative? See my new product dotenvx – that lets you:
- encrypt your .env files
- commit them to code
- and securely sync them over git
It works with a single command. Run npx dotenv-vault@latest push.
npx dotenv-vault@latest push
remote: Securely pushing (.env)... done
remote: Securely pushed development (.env)
remote: Securely built vault (.env.vault)
That's it. You securely synced your .env file. Next, tell your teammate to run npx dotenv-vault@latest pull
npx dotenv-vault@latest pull
Nice!
See further usage and commands.
When you make a change to your .env file, push it up.
$ npx dotenv-vault@latest push
Commit your .env.vault file safely to code.
$ git add .env.vault
$ git commit -am "Add .env.vault"
$ git push
Now your teammate can pull the latest .env changes.
$ git pull
$ npx dotenv-vault@latest pull
That's it!
Learn more about usage
Stop scattering your production secrets across multiple third-parties and tools. Instead, use an encrypted .env.vault file.
Generate your encrypted .env.vault file.
$ npx dotenv-vault@latest build
Fetch your production DOTENV_KEY.
$ npx dotenv-vault@latest keys production
remote: Listing .env.vault decryption keys... done
dotenv://:key_1234…@dotenv.org/vault/.env.vault?environment=production
Set DOTENV_KEY on your server.
# heroku example
heroku config:set DOTENV_KEY=dotenv://:key_1234…@dotenv.org/vault/.env.vault?environment=production
Commit your .env.vault file safely to code and deploy.
$ git add .env.vault
$ git commit -am "Update .env.vault"
$ git push
$ git push heroku main # heroku example
That's it! On deploy, your .env.vault file will be decrypted and its secrets injected as environment variables – just in time.
Learn more about deploying
After you've pushed your .env file, dotenv-vault automatically sets up multiple environments. Manage multiple environments with the included UI. learn more
$ npx dotenv-vault@latest open production
That's it! Manage your ci, staging, and production secrets from there.
Would you also like to pull your production .env to your machine? Run the command:
$ npx dotenv-vault@latest pull production
Learn more about environments
Vercel
Heroku
GitHub Actions
GitLab CI/CD
Netlify
Docker
Docker Compose
CircleCI
Serverless
Railway
Render
Travis CI
Google Cloud
Fly.io
Slack
Buddy
Cloud66
Digital Ocean
Dagger
Bitbucket
Node.js
Express
NextJS
Remix
Astro
Rails
Ruby
Sinatra
Flask
Python
Supabase
Pulumi
Angular
Nuxt
Vite
See more integration guides
$ npx dotenv-vault@latest help
newCreate your project at Dotenv Vault.
Example:
$ npx dotenv-vault@latest new
[DOTENV_VAULT]
Set .env.vault identifier. Defaults to generated value.
$ npx dotenv-vault@latest new vlt_6beaae5…
local: Adding .env.vault (DOTENV_VAULT)... done
local: Added to .env.vault (DOTENV_VAULT=vlt_6beaa...)
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
loginLog in to dotenv-vault.
Example:
$ npx dotenv-vault@latest login
[DOTENV_ME]
Set .env.me identifier. Defaults to generated value.
$ npx dotenv-vault@latest login me_00c7fa…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest login -y
logoutLog out of dotenv-vault.
Example:
$ npx dotenv-vault@latest logout
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest logout -y
pushPush .env securely.
Example:
$ npx dotenv-vault@latest push
[ENVIRONMENT]
Set environment to push to. Defaults to development
$ npx dotenv-vault@latest push production
[FILENAME]
Set input filename. Defaults to .env for development and .env.{environment} for other environments
$ npx dotenv-vault@latest push production .env.production
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest push --dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest push -y
pullPull .env securely.
Example:
$ npx dotenv-vault@latest pull
[ENVIRONMENT]
Set environment to pull from. Defaults to development
$ npx dotenv-vault@latest pull production
[FILENAME]
Set output filename. Defaults to .env for development and .env.{environment} for other environments
$ npx dotenv-vault@latest pull production .env.production
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest pull --dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest pull -y
If you want to pull a specific version you can do so. For example,
npx dotenv-vault@latest pull development@v14
openOpen project page.
Example:
$ npx dotenv-vault@latest open
[ENVIRONMENT]
Set environment to open to. Defaults to development.
$ npx dotenv-vault@latest open production
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest open -y
whoamiDisplay the current logged in user.
Example:
$ npx dotenv-vault@latest whoami
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest whoami dotenvMe=me_b1831e…
buildBuild .env.vault file.
Example:
$ npx dotenv-vault@latest build
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest build dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest build -y
keysList .env.vault decryption keys.
Example:
$ npx dotenv-vault@latest keys
[ENVIRONMENT]
Set environment. Defaults to all.
$ npx dotenv-vault@latest keys production…
remote: Listing .env.vault decryption keys... done
dotenv://:[email protected]/vault/.env.vault?environment=production
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest keys dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest keys -y
rotatekeyRotate DOTENV_KEY.
Example:
$ npx dotenv-vault@latest rotatekey production
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest rotatekey dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest rotatekey -y
decryptDecrypt .env.vault locally.
Example:
$ npx dotenv-vault@latest decrypt dotenv://:[email protected]/vault/.env.vault?environment=development
[DOTENV_KEY]
Set DOTENV_KEY to decrypt .env.vault. Development key will decrypt development, production will decrypt production, and so on.
$ npx dotenv-vault@latest decrypt dotenv://:[email protected]/vault/.env.vault?environment=development
versionsList version history.
Example:
$ npx dotenv-vault@latest versions
[ENVIRONMENT]
Set environment to check versions against. Defaults to development.
$ npx dotenv-vault@latest versions production
-m, --dotenvMe
Pass .env.me (DOTENV_ME) credential directly (rather than reading from .env.me file)
$ npx dotenv-vault@latest versions dotenvMe=me_b1831e…
-y, --yes
Automatic yes to prompts. Assume yes to all prompts and run non-interactively.
$ npx dotenv-vault@latest versions -y
If you want to pull a specific version you can do so. For example,
npx dotenv-vault@latest pull development@v14
.env.vault file not decrypting my environment variables successfully?First, make sure you are using [email protected] or greater. (If you are using a different language make sure you have installed one of its libraries.)
Second, test decryption is working locally.
$ npx dotenv-vault@latest decrypt dotenv://:[email protected]/vault/.env.vault?environment=production
# outputs environment variables
Third, test decryption on boot is working locally.
$ DOTENV_KEY='dotenv://:[email protected]/vault/.env.vault?environment=p
暂无开放 Issues,或尚未同步最近议题。