Securely manage .env files. Encrypt with AES-GCM, export inside
Steganography PNGs, and work entirely offline.
Privacy Notice: We do not store your keys. We do not see your data. Everything happens locally in your browser logic.
Select your encrypted .json or vault image .png.
Supports EnvVault JSON (v1) and Stego-PNGs.
Designed for secure, hassle-free secret sharing.
Once loaded, EnvVault requires zero internet functionality. You can even disconnect your Wi-Fi before typing secrets.
Hide your sensitive `.env` files inside innocent-looking images. Perfect for sharing secrets over email or Slack securely.
No CLI to install. No `npm install`. Works in Chrome, Firefox, Safari, and Edge instantly.
Your secrets never leave your browser unencrypted. We use the Web Crypto API for native performance and security.
We never see your password or your secrets. Encryption happens 100% in your browser using AES-GCM.
Industry-standard authenticated encryption. We generate a unique IV (Initialization Vector) for every single vault.
Your password is strengthened using PBKDF2 (SHA-256) with a random salt and high iteration count to resist brute-force attacks.
Hide your encrypted vault inside a harmless-looking PNG image. Perfect for sharing via public channels like Slack or Email.
Since no server is required, this tool works perfectly offline. You can even save the HTML file and run it locally.
Export as a standard JSON file containing the ciphertext, iv, and
salt. Easy to integrate into CI/CD pipelines.
Hints are stored as plain text in the vault file (JSON/PNG). This allows you to recall your password without exposing the key, but never put your actual password here.
No. Your password is used to derive an encryption key exclusively within your browser interactively. Neither the password nor the key is ever transmitted over the network.
Your data is lost forever. Because we use zero-knowledge encryption, there is no "password reset" or backdoor. We cannot recover your vault if you forget the password used to encrypt it.
Simply drag and drop the PNG image onto the "Decrypt" tab of this tool. Enter the password you used to encrypt it, and the hidden .env file will be extracted and decrypted instantly.
We use AES-GCM (Galois/Counter Mode) with a 256-bit key for encryption, which ensures both confidentiality and integrity. Keys are derived from your password using PBKDF2 with SHA-256.
Yes. This tool is ideal for sharing production secrets securely between team members without exposing them in chat logs or email storage. The generated JSON/PNG files can be safely stored in valid, insecure locations as long as the password is communicated via a separate secure channel.