{"_id":"@boltpl/envseal","name":"@boltpl/envseal","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@boltpl/envseal","version":"1.0.0","description":"encrypt secrets at rest, inject at runtime","main":"dist/cli.js","bin":{"envseal":"bin/envseal"},"scripts":{"build":"tsc","prepublishOnly":"tsc"},"keywords":["env","secrets","encryption","vault","dotenv","security"],"author":{"name":"mgrom"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/mgrom/envseal.git"},"homepage":"https://github.com/mgrom/envseal","engines":{"node":">=18"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.5.0"},"_id":"@boltpl/envseal@1.0.0","gitHead":"19bf504e3745835d8c86f87fe56d51a1124d03f6","types":"./dist/cli.d.ts","bugs":{"url":"https://github.com/mgrom/envseal/issues"},"_nodeVersion":"20.19.4","_npmVersion":"10.8.2","dist":{"integrity":"sha512-rK49YV+bqd9pcBI2pJ9ynXLjz5Ivf2RjrFspQ4yAZVaRFG7AtAky9hkg5YyR2kNyy+1e+c26XZgYh6he/zF1wQ==","shasum":"fa56e48aae2540af086a32aae9a1f60adae89d97","tarball":"https://registry.npmjs.org/@boltpl/envseal/-/envseal-1.0.0.tgz","fileCount":14,"unpackedSize":24517,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCVLLxPaeChlUiQWdcz+NYyX+gTvGHxgQIwNfmHGFq9iwIhAJ/DLS++aYsO0PDruCpbQDvLA1jhu8HpLFAUJwFE0r/E"}]},"_npmUser":{"name":"boltpl","email":"boltpl81@gmail.com"},"directories":{},"maintainers":[{"name":"boltpl","email":"boltpl81@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/envseal_1.0.0_1772020671730_0.6511356327436444"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-25T11:57:51.609Z","1.0.0":"2026-02-25T11:57:51.874Z","modified":"2026-02-25T11:57:52.119Z"},"maintainers":[{"name":"boltpl","email":"boltpl81@gmail.com"}],"description":"encrypt secrets at rest, inject at runtime","homepage":"https://github.com/mgrom/envseal","keywords":["env","secrets","encryption","vault","dotenv","security"],"repository":{"type":"git","url":"git+https://github.com/mgrom/envseal.git"},"author":{"name":"mgrom"},"bugs":{"url":"https://github.com/mgrom/envseal/issues"},"license":"MIT","readme":"# envseal\n\nencrypt secrets at rest, inject at runtime. no plaintext on disk.\n\n## install\n\n```bash\nnpm install -g envseal\n```\n\n## usage\n\n### passphrase mode (dev/laptop)\n\n```bash\nenvseal init\nenvseal set DATABASE_URL \"postgres://...\"\nenvseal set STRIPE_KEY \"sk_live_...\"\nenvseal run -- node server.js    # prompts for passphrase, injects env\n```\n\n### keyfile mode (servers)\n\n```bash\ncd ~/projects/myapp\nenvseal keygen              # generates ~/.envseal/keys/myapp.key (auto-named after directory)\nenvseal init --keyfile\nenvseal set DATABASE_URL \"postgres://...\"   # auto-finds key, no config needed\nenvseal run -- node server.js               # just works\n\n# in systemd unit - zero interaction\n# ExecStart=envseal run -- node server.js\n```\n\nkey is stored in `~/.envseal/keys/<project-dir>.key`, vault is `.envseal.vault` in project dir. separated by default.\n\n### other commands\n\n```bash\nenvseal get KEY              # decrypt single value\nenvseal list                 # show key names (not values)\nenvseal rm KEY               # remove a secret\nenvseal export               # decrypt all as KEY=VALUE on stdout\nenvseal import .env          # bulk import from .env file\nenvseal keygen --out PATH    # custom key location\n```\n\n## key resolution\n\nin keyfile mode, envseal looks for the key in order:\n\n1. `ENVSEAL_KEY` env var (base64 key directly)\n2. `ENVSEAL_KEY_FILE` env var (path to key file)\n3. `~/.envseal/keys/<project-dir-name>.key` (auto-resolve)\n\nin passphrase mode, same lookup order, then falls back to interactive prompt. `ENVSEAL_PASSPHRASE` env var skips the prompt.\n\n## how it works\n\nsecrets are encrypted with AES-256-GCM. in passphrase mode, the encryption key is derived via scrypt. in keyfile mode, the key is a random 256-bit value.\n\nthe vault (`.envseal.vault`) stores key names in plaintext, values as encrypted blobs. `envseal run` decrypts everything in memory, passes secrets as env vars to the child process, then exits. nothing plaintext touches disk.\n\nzero dependencies - uses only node's built-in `crypto` module.\n\n## vault format\n\n```json\n{\n  \"version\": 2,\n  \"keyMode\": \"keyfile\",\n  \"secrets\": {\n    \"DATABASE_URL\": { \"iv\": \"...\", \"data\": \"...\", \"tag\": \"...\" }\n  }\n}\n```\n\n## security model\n\nprotects secrets at rest and from automated exfiltration. scanners grepping for `.env`, `sk-`, `ghp_`, private keys find nothing.\n\nin keyfile mode, key and vault are in different locations with different permissions. attacker needs both.\n\nnot a defense against an active attacker with same-UID shell access. they can read `/proc/<pid>/environ` or attach a debugger. no userspace tool prevents that.\n\n## license\n\nMIT\n","readmeFilename":"README.md","_rev":"1-5596db64d7d5c305cfbadf343b622e51"}