What is AgentSecrets?
The Zero-Knowledge Difference
How AgentSecrets Works
Installation
Quick Start
Migrating from .env Files
Migrating from Vault / AWS
Migrating from dotenv-vault
Production Checklist
Credential Exposure
What Zero-Knowledge Means
The Proxy Model
The Three-Layer Model
Environments
Agent Identity
Storage Modes
The No get() Principle
Secret-Level Policies
Cloud Overview & Architecture
The Dual-Engine Model
Cloud Resolver Data Plane
Workload & Agent Tokens
Egress Allowlists & Audit Streams
Cloud REST API Reference
Account (init / login)
Server & Self-Hosting (server)
Docs
Shell Autocompletion
Keychain Auth
Secrets
Environments
Credential Proxy
env Injection
Workspaces & Teams
Projects
Agent Identity
Audit & Governance
Integrations Overview
Claude Desktop
Cursor
OpenClaw
HTTP Proxy (Any)
LangChain (Soon)
CrewAI (Soon)
CI/CD Pipeline
SDK Overview
Python SDK
Python API Reference
Python SDK Manual Testing
JavaScript SDK (Soon)
Ecosystem Overview
Zero-Knowledge MCP Server
Server Overview
5-Layer Architecture
Self-Hosting Guide
Authentication & Keys
Workspaces & Teams
Projects & Scope
Environments
Secrets & Sync Protocol
Agent Identity Resolution
Telemetry & Metrics Engine
Audit Log Sync
API Endpoint Reference
Security Overview
Anti-Impersonation & Process Verification
Encryption Model
Zero-Knowledge Sync
Proxy Security Layers
Threat Model
OWASP Top 10 Mitigation
Security FAQ
Third-Party Audit
Reporting Vulnerabilities
Guides Overview
Building on the SDK
Stripe Integration
OpenAI Integration
Multi-Agent Setup
Onboarding Team
CI/CD Pipeline
Publishing ZK MCP
Rotating Credentials
Auditing Team Activity
Dev to Production
Kubernetes Deployment
Monorepo Setup
Production Proxy Hardening
vs .env Files
vs HashiCorp Vault
vs AWS Secrets Manager
vs dotenv-vault
vs Infisical
When Not to Use
Proxy Not Starting
Proxy Not Resolving
Domain Blocked
Sync Conflicts
MCP Not Connecting
Session Token Errors
Proxy Session Authorization
Keychain Storage & Backends
SSRF & Destination Rules
Installation Issues
Error Codes Reference
Frequently Asked Questions
v3.1.x
v3.0.0
v2.1.0
v2.0.0
v1.4.0
v1.3.x
v1.2.0
v1.1.x
v1.0.x
Getting StartedMigrating from dotenv-vault

Migrating from dotenv-vault

dotenv-vault is a tool for sharing encrypted .env files across a team. While it simplifies dotenv management, it still relies on loading plaintext credentials directly into process environment variables (process.env or os.environ), exposing them to security risks in development and AI-assisted workflows.

This guide walks you through migrating from dotenv-vault to AgentSecrets, achieving a zero-knowledge setup where secrets are secured in your local OS Keychain and injected only when and where they are needed.


Architectural Comparison

Featuredotenv-vaultAgentSecrets
Storage LocationDecrypted local .env files / Process memorySecure OS Keychain (no plaintext files)
Team SynchronizationCloud-stored keys decrypting .env.vaultEnd-to-End Encrypted (E2E) zero-knowledge sync
Runtime AccessExposes all secrets to the process environmentProxy transport-layer injection OR runtime execution spawning
Vulnerability to Code InspectionHigh (any tool can print process.env / .env files)Eliminated (secrets never exist in the filesystem or target process memory)

Step-by-Step Migration

1Retrieve decrypted credentials

Ensure you have your current decrypted secrets loaded locally. If you do not have a local .env file, run the decrypt command using the dotenv-vault CLI:

npx dotenv-vault decrypt

2Initialize AgentSecrets workspace

Initialize a new project and workspace in your project directory:

agentsecrets init

3Import your secrets

Push your decrypted local .env file into AgentSecrets. This command automatically encrypts each credential value locally and stores it in your secure OS Keychain:

agentsecrets secrets push

Verify they have been imported correctly:

agentsecrets secrets list

4Remove dotenv-vault files and keys

Clean up your repository by deleting the dotenv-vault configuration and encrypted keys:

rm .env.vault .env.project .env.keys .env

Remove any DOTENV_KEY environment variables from your shell profile, system environment, or hosting provider configuration.

5Update your code integration

Remove the dotenv-vault setup from your application code:

Before (Node.js):

require('dotenv-vault').config(); // Secrets are now exposed in process.env

After (Zero-Knowledge CLI Environment Injection): Simply launch your app prefixing it with the AgentSecrets runtime execution command:

agentsecrets env -- node app.js

After (Zero-Knowledge Proxy Integration): Configure your application to query external APIs through the local proxy:

const response = await fetch('http://localhost:8765/proxy', { headers: { 'X-AS-Target-URL': 'https://api.stripe.com/v1/balance', 'X-AS-Inject-Bearer': 'STRIPE_KEY' } });

Zero-Knowledge Advantages

By completing this migration, you secure your developer environment:

  • No Plaintext Leakage: Plaintext credentials never reside on your local storage drive, preventing scanning or git-commit accidents.
  • Role-Based Workspaces: Securely manage multiple environment scopes (development, staging, production) from a single CLI without shuffling .env files.
  • Complete Audit Trail: Every access attempt and API call is cryptographically audited, giving your team full visibility into where and how secrets are utilized.
Was this helpful?
Thanks for your feedback!
Your feedback helps us improve the platform.