Security Tutorial

Env Secrets Manager: The Secure Way to Share .env Files

Last updated: 2026-03-12

Sharing sensitive configuration files via Slack or Email is a security risk. Learn how to encrypt them locally using AES-GCM and hide them inside images.

🛠️ Developer's Note

I built Env Vault because I watched a teammate paste production database credentials into a Slack channel. Every team I've been on has had this problem — the 'can you send me the .env file?' question always leads to plaintext secrets in chat logs. This tool eliminates that risk with zero-knowledge client-side encryption.


Every developer knows the struggle. You have a local .env file with API keys, database credentials, and secret tokens. A new team member joins, and the question inevitable comes up: "Can you send me the .env file?"

What happens next is often a security nightmare. Files get dropped into Slack, pasted into Notion, or emailed. These secrets now live on third-party servers, in chat logs, and in download folders, often unencrypted.

We built Env Secrets Manager to solve this problem without requiring you to set up complex infrastructure like HashiCorp Vault for simple projects.

What is Env Secrets Manager?

Env Secrets Manager is a browser-based tool that encrypts your configuration files using AES-GCM (Advanced Encryption Standard in Galois/Counter Mode).

Unlike other tools, it works entirely offline. Your data never leaves your browser. The "encryption" doesn't happen on a server; it happens right inside your Chrome or Firefox window using the Web Crypto API.

Why Client-Side Security Matters

Trust is hard. When you paste a password into a website, how do you know they aren't logging it?

With Client-Side encryption, you don't have to trust the server.

  • Zero Knowledge: Since the server never receives the key, it cannot decrypt your data even if it wanted to.
  • No Network Requests: You can literally disconnect your WiFi after loading the page, and the tool will still work perfectly.
  • Auditability: Because the code runs in your browser, you can inspect the network tab to verify that no data is being exfiltrated.

How to Use

1. Encrypting a File

1. Open Env Secrets Manager.
2. Click "Create New Vault".
3. Paste your .env content into the secure editor.
4. Click "Encrypt & Export".
5. Enter a strong Master Password.

2. Decrypting a File

1. Drag and drop the .json or .png file onto the tool.
2. Enter the Master Password.
3. The original content is restored instantly.

Advanced Features

Steganography (Hidden in Plain Sight)

This is our favorite feature. You can export your encrypted vault as a PNG image. The encrypted data is hidden inside the image pixels or metadata. To anyone else, it looks like a cool piece of generative art. To the tool, it contains your secrets.

Portable JSON

For DevOps workflows, you can export a raw JSON file containing the ciphertext, the iv (Initialization Vector), and the salt. This is perfect for committing encrypted secrets to a repository, provided you manage the password separately.

Security Deep Dive

The Algorithms

We use the SubtleCrypto interface of the Web Crypto API:

  • Encryption: AES-GCM with 256-bit keys. GCM provides authenticated encryption, meaning any tampering with the ciphertext is detected.
  • Key Derivation: PBKDF2 (Password-Based Key Derivation Function 2) with SHA-256 and high iteration counts to resist brute-force attacks.
  • Randomness: All salts and IVs are generated using crypto.getRandomValues(), ensuring cryptographically strong randomness.

A Note on Public Hints

When creating a vault, you can add a "Public Hint". Crucial Warning: This hint is stored as plain text in the file's metadata. It is visible to anyone who has the file, even without the password. Use it for memory joggers like "The name of our first office", but NEVER put the password itself or any part of the secret in the hint.

Limitations / When NOT to Use This

  • If you forget your master password, the encrypted vault is permanently unrecoverable — there is no password reset or recovery mechanism by design (zero-knowledge architecture)
  • The steganography export (hiding secrets in PNG images) adds ~2x to the file size compared to the JSON export — large vaults may produce multi-megabyte PNG files
  • Browser-based encryption means the tool is only as secure as your browser environment — if your device has malware or a compromised browser extension, client-side encryption won't protect you
  • Not a replacement for proper secrets management in production (HashiCorp Vault, AWS Secrets Manager) — this tool is designed for secure sharing between developers, not runtime secret injection