Why you should encrypt .env files before committing
Committing a plaintext .env file to Git exposes API keys, database passwords and third-party tokens. Even a private repository can leak, and once a secret lands in Git history it is very hard to remove.
Encrypting the file turns it into a vault that only someone with your decryption key can open. You keep the key on your machine and commit the ciphertext safely, so the repository stays shareable without leaking anything.
- API keys and OAuth secrets never appear in Git history
- Team members without the key cannot read the values
- The
.env.vaultfile is safe to store on remote hosts - Deploys stay reproducible when the key is provided at runtime