Encrypt your .env file online

AES-256-GCM vault, byte-identical to the CLI. The vault updates live as you type, and your plaintext and key never leave this tab.

Free tool · Updated August 2026 · No account required

How It Works

1

Add your .env and a key

Paste the file, then use a 64-char hex key, a raw 32+ byte string, or a passphrase.

2

Read the live vault

The # envy:v1 vault builds in real time with AES-256-GCM and a fresh random nonce.

3

Copy or download

Save .env.vault, commit it to Git, and share the key out-of-band.

Env encrypt

Live encryption, 100% in your browser

.env
5 lines · 109 chars runs locally in your browser
Secret key
256-bit hex key Anyone with this key can decrypt the vault. There is no recovery.

Algorithm

AES-256

Mode

GCM

Key strength

256-bit

Keys stored

0

.env.vault

Add a .env and a secret key above and the vault appears here.

Encrypted locally

Even golive.ly cannot read this vault without your key

4 keys encrypted · 256-bit hex key

Runs locally in your browser

Why you should encrypt .env files before committing

Committing a plaintext .env file to Git exposes API keys, database passwords and third-party tokens. Even a private repository can leak, and once a secret lands in Git history it is very hard to remove.

Encrypting the file turns it into a vault that only someone with your decryption key can open. You keep the key on your machine and commit the ciphertext safely, so the repository stays shareable without leaking anything.

  • API keys and OAuth secrets never appear in Git history
  • Team members without the key cannot read the values
  • The .env.vault file is safe to store on remote hosts
  • Deploys stay reproducible when the key is provided at runtime

How .env encryption works

Envy encrypts with AES-256-GCM entirely in your browser using the Web Crypto API. The encrypted file starts with the # envy:v1 header, and only someone holding your key can decrypt it back to the original .env.

Your plaintext and your key never leave this tab. The CLI uses the exact same format, so a file encrypted here decrypts with envy decrypt, and a vault created by the CLI opens right here. Pair the key with the secret generator for fresh 256-bit material.

Frequently Asked Questions

Common questions about encrypting .env files

No. Encryption happens entirely in your browser with the Web Crypto API. Your key never leaves this tab and is never transmitted to any server.