{"_id":"@alephic/dotenvx-next","_rev":"3-b39c3cf95a6b49de7fef2311c4735eb0","name":"@alephic/dotenvx-next","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@alephic/dotenvx-next","version":"0.1.0","keywords":["dotenvx","nextjs","vercel","env"],"license":"MIT","_id":"@alephic/dotenvx-next@0.1.0","maintainers":[{"name":"gmathieu","email":"contact@gmathieu.com"}],"dist":{"shasum":"21678cc8305a0a798d1ce268cb07fef8743be924","tarball":"https://registry.npmjs.org/@alephic/dotenvx-next/-/dotenvx-next-0.1.0.tgz","fileCount":8,"integrity":"sha512-dhCnrQpMAfoEUKDdixb5pKjVjjPyz75GVY1xtjzbEMASHelVHuDBarNJa5gPW0umP7xPEybzUaYQkfq8WD3+1g==","signatures":[{"sig":"MEUCICZaK/THMgt3GopojkxlePi7h68/5irSF9Zb6OKVZ7UoAiEAhhk1NFaAvXPDW3ZtOLpxYysnNlATbXjh+6FTZzUzjhg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":18713},"type":"module","engines":{"node":"24.x"},"exports":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"scripts":{"lint":"eslint --fix . && prettier --write --log-level=error . && tsc6","test":"vitest","build":"tsdown"},"_npmUser":{"name":"gmathieu","email":"contact@gmathieu.com"},"repository":{"url":"git+https://github.com/alephic-ai/dotenvx-next.git","type":"git"},"description":"Decrypt dotenvx env files at runtime in Next.js apps, with no generated .env file","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.3","eslint":"10.7.0","tsdown":"0.22.13","vitest":"4.1.10","prettier":"3.9.6","@eslint/js":"10.0.1","typescript":"npm:@typescript/typescript6@6.0.2","@types/node":"24.13.0","@changesets/cli":"2.31.1","eslint-plugin-n":"18.2.2","@dotenvx/dotenvx":"2.3.4","typescript-eslint":"8.65.0","eslint-plugin-import-x":"4.17.1","prettier-plugin-sort-json":"4.2.0","eslint-plugin-perfectionist":"5.10.0","prettier-plugin-packagejson":"3.0.2","@changesets/changelog-github":"0.7.0","eslint-import-resolver-typescript":"4.4.5"},"peerDependencies":{"next":">=15","@dotenvx/dotenvx":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/dotenvx-next_0.1.0_1787882472175_0.03668412412428035","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@alephic/dotenvx-next","version":"0.2.0","keywords":["dotenvx","nextjs","vercel","env"],"license":"MIT","_id":"@alephic/dotenvx-next@0.2.0","maintainers":[{"name":"gmathieu","email":"contact@gmathieu.com"}],"dist":{"shasum":"22f5e5d007d77812003329258507fd742d7510b8","tarball":"https://registry.npmjs.org/@alephic/dotenvx-next/-/dotenvx-next-0.2.0.tgz","fileCount":8,"integrity":"sha512-acJSIxN+DpDkMJ63DVVQAlc8GGjSBBSiNP79PxO3BMArHPObJIL18TLl9HTHLCAz6yYnp08Ub4NOBLbKXkgczA==","signatures":[{"sig":"MEYCIQCAFbrayVYP1VpdenFmH8wtMdtbQvAfpGgLB539yz7ifwIhAI4ZVq+xDuURsZsW6JZirpQnloNbT4w4rwEUjFbL4OyN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@alephic%2fdotenvx-next@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":18713},"type":"module","engines":{"node":"24.x"},"exports":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"scripts":{"lint":"eslint --fix . && prettier --write --log-level=error . && tsc6","test":"vitest","build":"tsdown"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f9dc5aeb-9008-4250-811a-759da15d36c0"}},"repository":{"url":"git+https://github.com/alephic-ai/dotenvx-next.git","type":"git"},"description":"Decrypt dotenvx env files at runtime in Next.js apps, with no generated .env file","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.3.3","eslint":"10.7.0","tsdown":"0.22.13","vitest":"4.1.10","prettier":"3.9.6","@eslint/js":"10.0.1","typescript":"npm:@typescript/typescript6@6.0.2","@types/node":"24.13.0","@changesets/cli":"2.31.1","eslint-plugin-n":"18.2.2","@dotenvx/dotenvx":"2.3.4","typescript-eslint":"8.65.0","eslint-plugin-import-x":"4.17.1","prettier-plugin-sort-json":"4.2.0","eslint-plugin-perfectionist":"5.10.0","prettier-plugin-packagejson":"3.0.2","@changesets/changelog-github":"0.7.0","eslint-import-resolver-typescript":"4.4.5"},"peerDependencies":{"next":">=15","@dotenvx/dotenvx":"^2.3.0"},"_npmOperationalInternal":{"tmp":"tmp/dotenvx-next_0.2.0_1787882917232_0.661053715452695","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@alephic/dotenvx-next","version":"0.2.1","description":"Decrypt dotenvx env files at runtime in Next.js apps, with no generated .env file","keywords":["dotenvx","nextjs","vercel","env"],"repository":{"type":"git","url":"git+https://github.com/alephic-ai/dotenvx-next.git"},"license":"MIT","type":"module","exports":{"types":"./dist/index.d.mts","default":"./dist/index.mjs"},"devDependencies":{"@changesets/changelog-github":"0.7.0","@changesets/cli":"2.31.1","@dotenvx/dotenvx":"2.3.4","@eslint/js":"10.0.1","@types/node":"24.13.0","eslint":"10.7.0","eslint-import-resolver-typescript":"4.4.5","eslint-plugin-import-x":"4.17.1","eslint-plugin-n":"18.2.2","eslint-plugin-perfectionist":"5.10.0","next":"16.3.3","prettier":"3.9.6","prettier-plugin-packagejson":"3.0.2","prettier-plugin-sort-json":"4.2.0","tsdown":"0.22.13","typescript":"npm:@typescript/typescript6@6.0.2","typescript-eslint":"8.65.0","vitest":"4.1.10"},"peerDependencies":{"@dotenvx/dotenvx":"^2.3.0","next":">=15"},"engines":{"node":"24.x"},"publishConfig":{"access":"public"},"scripts":{"build":"tsdown","lint":"eslint --fix . && prettier --write --log-level=error . && tsc6","test":"vitest"},"_nodeVersion":"24.19.0","_id":"@alephic/dotenvx-next@0.2.1","dist":{"integrity":"sha512-2TQbvOZgxSga582ZqPW/qELV53eBNzPwksBD2fPzxU5t1VrlpCMc++Ev2+TsVvfI9Kj4aRs+8SBHOh0g2q1g/Q==","shasum":"1e01e8e639c4747601f990b406f0309a029fb7b2","tarball":"https://registry.npmjs.org/@alephic/dotenvx-next/-/dotenvx-next-0.2.1.tgz","fileCount":8,"unpackedSize":20237,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@alephic%2fdotenvx-next@0.2.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIACRGIJfBS9is7e+4i3BvjQhFsAvWCu4+dWBJgpr4TGXAiEA1fFOweNABy+4e9I1BEFFCQDHuJctG5jNvaNThBNeyU8="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f9dc5aeb-9008-4250-811a-759da15d36c0"}},"directories":{},"maintainers":[{"name":"gmathieu","email":"contact@gmathieu.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dotenvx-next_0.2.1_1787946551556_0.03810596966372204"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-28T02:01:12.006Z","modified":"2026-08-28T19:49:12.057Z","0.1.0":"2026-08-28T02:01:12.325Z","0.2.0":"2026-08-28T02:08:37.379Z","0.2.1":"2026-08-28T19:49:11.717Z"},"license":"MIT","keywords":["dotenvx","nextjs","vercel","env"],"repository":{"type":"git","url":"git+https://github.com/alephic-ai/dotenvx-next.git"},"description":"Decrypt dotenvx env files at runtime in Next.js apps, with no generated .env file","maintainers":[{"name":"gmathieu","email":"contact@gmathieu.com"}],"readme":"# @alephic/dotenvx-next\n\nDecrypt [dotenvx](https://dotenvx.com/) env files at runtime in Next.js apps —\nno generated `.env` file, no second parser, one loader for dev, build and\ndeployed functions.\n\n## Why\n\n`dotenvx run -- next build` only decorates the build process. On Vercel the\nfunction starts with the platform env alone, so nothing decrypts `dotenv/` for\nit. Baking a `.env` file at build time hands the values to Next's own loader,\nwhich parses them with a different grammar (`$`, `\"` and `\\` get mangled).\n\n[dotenvx's Next.js guide](https://dotenvx.com/docs/nextjs/) recommends a third\nroute: override `@next/env` with `@dotenvx/next-env` via package-manager\n`overrides`. That fixes both problems, but by replacing a Next internal, which\nhas costs this package avoids:\n\n- **It is a fork of `@next/env`, not a wrapper.** The published bundle copies\n  Next's `loadEnvConfig`/`processEnv`/`resetEnv` and swaps the parser. When Next\n  changes those internals (it has: `onReload`, `__NEXT_PRIVATE_*` handling, FIFO\n  detection), the override keeps \"working\" while diverging, and the failure\n  surfaces at runtime on Vercel — after a Next upgrade that touched nothing\n  env-related.\n- **It only reads root `.env*` files** in Next's fixed order\n  (`.env.<mode>.local`, `.env.local`, `.env.<mode>`, `.env`), with `mode` one of\n  `development`/`production`/`test`. A `dotenv/` folder or a `.env.preview` for\n  Vercel previews has no equivalent.\n- **Overrides are per-consumer and fragile.** Every app carries the override\n  (pnpm 11: in `pnpm-workspace.yaml`, not `package.json`), every `next` bump\n  becomes a \"does the override still match\" event, and dotenvx's own docs note\n  that package managers apply overrides inconsistently.\n- **It bundles a second dotenvx.** A minified copy of `@dotenvx/primitives`\n  ships inside the override, separate from the `@dotenvx/dotenvx` CLI the app\n  encrypts with. Its source is no longer in the dotenvx monorepo; only the\n  bundle is inspectable.\n\nThis package touches nothing inside Next. It makes the app decrypt its own\ncommitted files, with the private key that is already a platform env var, and\ntells Next to ship those files with each function. Next's loader is never\ninvolved, so there is nothing to keep in sync across Next releases.\n\n## Installation\n\n```bash\npnpm add @alephic/dotenvx-next @dotenvx/dotenvx\n```\n\n`@dotenvx/dotenvx` is a peer dependency so the CLI you encrypt with and the\nruntime that decrypts are the same copy.\n\nExpects the\n[Alephic layout](https://github.com/alephic-ai/tools/blob/main/doc/env-vars-and-secrets.md):\nencrypted files in `dotenv/` (`.env`, `.env.production`, `.env.preview`,\n`.env.local`), keys named `DOTENV_PRIVATE_KEY`, `DOTENV_PRIVATE_KEY_PRODUCTION`,\n… in the environment.\n\n### Why `dotenv/` and not the project root\n\nMany CLIs auto-load a root `.env` — Next.js, Vite, Prisma, drizzle-kit, Vercel\nCLI, `node --env-file`, and anything built on `dotenv`. None of them can decrypt\ndotenvx values, so with encrypted files in the root they would silently inject\nthe literal `encrypted:…` strings into `process.env`: a `DATABASE_URL` that\nlooks set but isn't, failing somewhere downstream instead of at the source.\nKeeping the files in `dotenv/` makes every load explicit — this package for\nNext, `dotenvx run -f dotenv/...` for everything else — and nothing picks them\nup by accident.\n\n## Usage\n\n```ts\n// next.config.ts\nimport { withDotenvx } from '@alephic/dotenvx-next'\n\nexport default withDotenvx(nextConfig)\n// with other wrappers, innermost:\n// withWorkflow(withPayload(withDotenvx(nextConfig)))\n```\n\n```ts\n// src/env.ts — before anything reads process.env\nimport { loadEnv } from '@alephic/dotenvx-next'\nloadEnv()\n\nexport const env = createEnv({ /* … */ runtimeEnv: process.env })\n```\n\nThen `dev`, `build` and `start` no longer need a dotenvx CLI wrapper. Keep\n`dotenvx run -- …` for tools that don't go through Next (`drizzle-kit`,\n`vitest`, scripts).\n\n`loadEnv()` is a no-op when `NODE_ENV` is `test`, so importing `env.ts` from a\ntest never decrypts `dotenv/` with whatever private key the machine has. Seed\nthe test env explicitly (a vitest `setupFiles` entry), or run the test command\nunder `dotenvx run -- …` when it needs real values.\n\n## How it works\n\n- `withDotenvx()` calls `loadEnv()` while `next.config.ts` is evaluated — in the\n  Next CLI process, before the compiler starts — so `NEXT_PUBLIC_*` values are\n  inlined and every server module sees the env. It also traces `dotenv/.env`,\n  `.env.production` and `.env.preview` into every server function and marks\n  dotenvx as an external package.\n- `loadEnv()` in `env.ts` covers deployed functions, where the config file is\n  not executed: on first import it reads the traced files and decrypts them.\n- Precedence, first match wins: `process.env` → `dotenv/.env.${VERCEL_ENV}` →\n  `dotenv/.env.local` → `dotenv/.env`. Platform-injected values (integrations)\n  always win. Repeated calls are no-ops.\n- When `VERCEL_ENV` is set, a missing `dotenv/.env` or a failed decrypt throws\n  (`[MISSING_ENV_FILE]`, `[DECRYPTION_FAILED]`) on the first request. Without it\n  — no `dotenv/` yet, CI without keys, `next typegen` on a fresh clone — missing\n  files are skipped, decrypt errors are logged, execution continues.\n- Under `NODE_ENV=test` nothing is read at all. Next never sets that value; only\n  a test runner does.\n\nNot for `proxy.ts`/middleware or edge routes: Next does not apply\n`outputFileTracingIncludes` to the proxy trace (verified with Turbopack, Next\n16.3), so that function has no `dotenv/` files and sees platform env only. Keep\nsecrets used there in the platform's env vars.\n","readmeFilename":""}