dotenvnest
v2.0.2
Published
A secure CLI to manage your .env files
Downloads
154
Maintainers
Readme
DotEnvNest CLI lets you push, pull, view, diff, and share encrypted environment variables directly from your terminal. Backed by client-side/PIN-derived AES-256 encryption, your secrets are stored safely in the cloud and synced effortlessly.
Shorthand Alias: You can use either
dotenvnestordenfor every command!
🚀 Quick Install
Global Installation
# Using npm
npm install -g dotenvnest
# Using pnpm
pnpm add -g dotenvnest
# Using yarn
yarn global add dotenvnestOr run directly with npx (No installation needed)
npx dotenvnest --help⚡ Quick Start
# 1. Authenticate with your browser
dotenvnest login
# 2. Push your local .env to cloud
dotenvnest push my-project
# 3. Pull it on another machine / directory
dotenvnest pull my-project
# 4. View secrets safely in the terminal
dotenvnest view my-project
# 5. Check differences between local and cloud
dotenvnest diff my-project📖 Command Reference
login — Authenticate CLI
Securely authenticates your CLI via the browser. If you're already logged in to the DotEnvNest Web App, it connects automatically with one click.
dotenvnest login
# or
den loginpush <project-name> — Upload .env file
Reads your local .env file, encrypts it, and saves it to your DotEnvNest account.
dotenvnest push my-api
# or
den push my-api
# Push specific file variant (e.g. .env.local, .env.production)
dotenvnest push my-api -f .env.local
den push my-api -f .env.stagingOptions:
-f, --file <filename>: Specify custom env file (default:.env).--owner <email>: Target a shared project when permissions allow editing.
pull <project-name> — Download .env file
Downloads and decrypts the environment variables from DotEnvNest to your local file. Includes overwrite confirmation and fuzzy project name matching.
dotenvnest pull my-api
# or
den pull my-api
# Output to a specific file
dotenvnest pull my-api -f .env.local
den pull my-api -f .env.productionOptions:
-f, --file <filename>: Specify destination file name (default:.env).--owner <email>: Specify the owner's email for shared projects in case of duplicate names.
view <project-name> — Inspect secrets in terminal
Displays the decrypted environment variables in a clean, formatted terminal box without writing to disk.
dotenvnest view my-api
# or
den view my-apiOptions:
--owner <email>: Specify the owner's email for shared projects.
diff <project-name> — Compare local vs. cloud
Compares your local .env with the version stored in DotEnvNest, color-coding added (+), removed (-), or modified (~) keys.
dotenvnest diff my-api
# or
den diff my-api -f .env.localOptions:
-f, --file <filename>: Specify local file to compare (default:.env).--owner <email>: Specify owner email for shared projects.
find [query] — List & search projects
Lists all projects you own as well as projects shared with you. You can filter with fuzzy search query.
# List all projects
dotenvnest find
# Search for specific projects
dotenvnest find backend
# or
den find apishare <project-name> <emails> — Share project access
Share a project with teammates using comma-separated emails. Assign either read or edit permissions.
# Read-only access
dotenvnest share my-api "[email protected]" --access read
# Multiple emails with edit access
dotenvnest share my-api "[email protected], [email protected]" --access edit
# or
den share my-api "[email protected]" --access editOptions:
--access <level>: Permission level (readoredit, default:read).
unshare <project-name> <emails> — Revoke access
Revoke access from one or more users on a project you own.
dotenvnest unshare my-api "[email protected]"
# or
den unshare my-api "[email protected], [email protected]"leave / exit <project-name> — Leave shared project
Remove yourself from a project shared by another user.
dotenvnest leave my-shared-project
# or
den leave my-shared-projectdel / delete <project-name> — Delete project
Permanently deletes a project you own after a safety confirmation prompt.
dotenvnest del my-old-project
# or
den delete my-old-projectdocs — Open online documentation
Opens the full web documentation in your default browser.
dotenvnest docs
# or
den docslogout — Clear session
Clears your local credentials and logs you out of the CLI.
dotenvnest logout
# or
den logout💡 Advanced Features & Tips
1. File Variants Auto-Mapping (-f / --file)
When pushing or pulling file variants with extensions (such as .env.local, .env.production), the CLI automatically handles naming variants cleanly:
# Pushes to cloud project "my-api"
dotenvnest push my-api
# Automatically maps to cloud project "my-api.local"
dotenvnest push my-api -f .env.local
# Automatically maps to cloud project "my-api.production"
dotenvnest push my-api -f .env.production2. Resolving Name Collisions (--owner)
If you have a project named backend and a teammate also shared a project named backend with you:
# Pulls YOUR backend project
dotenvnest pull backend
# Pulls your TEAMMATE'S backend project
dotenvnest pull backend --owner [email protected]3. Project Names with Spaces
Wrap project names containing spaces in double quotes:
dotenvnest pull "E-Commerce Backend"
dotenvnest push "Mobile App API"🤖 CI/CD & Automation (GitHub Actions, Vercel, Docker)
To use DotEnvNest in headless environments without interactive browser login:
- Obtain your token after running
dotenvnest loginlocally (stored in~/.dotenvnest-config.json). - Add it as an environment variable or repository secret named
DOTENVNEST_TOKEN.
GitHub Actions Example:
name: Deploy Application
on:
push:
branches: [main]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
# Pull .env file seamlessly
- name: Fetch Environment Variables
env:
DOTENVNEST_TOKEN: ${{ secrets.DOTENVNEST_TOKEN }}
run: npx dotenvnest pull my-production-api -f .env
- name: Build & Test
run: |
npm ci
npm run build🔒 Security Architecture
- Zero-Knowledge Encryption: Environment variables are encrypted using AES-256-CBC derived from your personal security PIN. The server never stores your unencrypted secrets or raw PIN.
- Secure Local Storage: CLI credentials stored in
~/.dotenvnest-config.jsonare restricted with POSIX0600permissions (owner read/write only). - Session Tokens: Short-lived JWTs authenticated against protected endpoints.
🔗 Useful Links
- 🌐 Web App: https://dotenvnest.vercel.app
- 📚 Documentation: https://dotenvnest.vercel.app/docs
- 🐙 GitHub Repository: muhammadsaif7717/dotenvnest
📝 License
Distributed under the MIT License. Created with ❤️ by MD. SAIF ISLAM.
