Environment Variable Encryptor
Encrypt environment variable examples, generate safe encryption key templates, and learn env encryption for Python, PowerShell, Lambda, Jenkins, and Terraform.
Secret Generator
Local Only: This tool runs entirely in your browser using the Web Crypto API. It generates random values suitable for local development. For production, you should rely on an enterprise Key Management Service (KMS) like AWS Secrets Manager or HashiCorp Vault.
Base64 is NOT Encryption:Base64 is merely an encoding scheme. It does not provide any cryptographic security. Do not use Base64 to "hide" secrets.
Generated Secrets
No secrets generated yet.
Select an option on the left to securely generate a random string directly in your browser.
Quick Summary
What is this tool?
By default, no, environment variables are not encrypted. Environment variables are stored in plain text in memory by the operating system and in .env files on your disk. Anyone with access to the server, the process list, or the file system can read them.
Some platforms (like AWS Lambda, GitHub Actions, or Vercel) encrypt environment variables at rest in their databases, but they decrypt them before injecting them into your application's memory at runtime.
Binary Encryption Keys & Sizes
When generating an encryption key, you usually choose between 128-bit, 192-bit, or 256-bit keys (for AES).
- 128-bit key: 16 bytes. Highly secure, slightly faster.
- 256-bit key: 32 bytes. Considered quantum-resistant and the standard for top-secret data.
Keys should be generated using a cryptographically secure pseudo-random number generator (CSPRNG), like the browser's Web Crypto API or Node.js crypto.randomBytes(). Deriving a key from a human-readable password requires a Key Derivation Function (like PBKDF2 or Argon2) with a salt.
How to Use This Tool
If you must encrypt environment variables yourself (e.g., to commit them to a repository safely, like Mozilla SOPS or Rails Credentials do), you follow this pattern:
- Generate an Encryption Key: Use a strong algorithm (like AES-256) to generate a binary encryption key. Do NOT use
Math.random()or weak passwords. - Encrypt the Value: Use the key to encrypt the secret value. The output is usually Base64-encoded so it can be stored as a string.
- Store the Ciphertext: Store the encrypted string in your
.envfile (e.g.,API_KEY=ENC[base64_string]). - Provide the Key at Runtime: The application must have the decryption key at runtime (via a secure vault, a KMS provider, or a highly restricted environment variable) to decrypt the value before using it.
Platform-Specific Encryption Notes
- Python: You can use the
cryptographylibrary (Fernet) to encrypt and decrypt environment variables.FERNET_KEYmust be injected securely at runtime. - PowerShell / Windows: Windows provides the Data Protection API (DPAPI) and
ConvertFrom-SecureStringto encrypt variables tied to a specific user account or machine. - AWS Lambda: AWS Lambda encrypts environment variables at rest using AWS KMS. You can also configure Lambda to encrypt variables in transit (client-side encryption) using KMS before Lambda receives them.
- Jenkins: Jenkins provides the "Secret text" credential type. Jenkins encrypts these values on disk (in
credentials.xml) using a master key and only decrypts them during a job execution. - Terraform: Terraform state files contain environment variables in plain text. You should configure a remote backend (like S3) with KMS encryption enabled to protect Terraform state.
Security Notes
- Never store the encryption key beside encrypted values. If your
.envfile contains both the encrypted secret and the key to decrypt it, the encryption is useless. - Local Browser Generation: This tool uses the Web Crypto API to generate random keys and evaluate entropy. We do not use
Math.random()for cryptographic keys. - No Server Logs: We do not log, store, or transmit your inputs. Keys are generated client-side and lost when you refresh the page.
- Use Secret Managers: For production, avoid manual encryption schemes. Use AWS Secrets Manager, HashiCorp Vault, Azure Key Vault, or Kubernetes Secrets to handle encryption and access control automatically.
How We Keep Your Configs Safe & Valid
Built-in Error Checking
Every file is checked against official rules. We catch missing fields and bad syntax. YAML indentation errors are flagged right away. Kubernetes, Terraform, and Docker specs are all covered. API versions and labels are verified too. You get valid output every time you generate.
100% Private & Local
All tools run in your browser only. Your API keys never leave your machine. We do not use any tracking scripts. No data is sent to any server. Passwords and secrets stay on your device. Crypto operations use the Web Crypto API. Your privacy is fully protected at all times.
Secure Settings by Default
Configs use safe defaults out of the box. Containers run as non-root users. Root filesystems are set to read-only. Dangerous Linux capabilities are dropped. Network policies limit pod-to-pod traffic. TLS 1.3 is enabled for web servers. Security headers are added where needed.
Ready for CI/CD & Git
Output files are ready for your Git repo. Use them with ArgoCD, Flux, or GitHub Actions. Files use clear formatting and comments. Code review is easy for your team. Indentation and key order are consistent. Test in staging before going to production. Every file is clean and well-structured.
Infrastructure as Code
Store configs in Git alongside your code. Terraform modules include typed variables. Backend configs support remote state locking. Outputs work across multiple modules. Ansible playbooks use clear task steps. Chef and Puppet configs are also supported. Every file works with version control tools.
Monitoring & Tracing
Set up Prometheus with auto-discovery rules. Create Grafana dashboards with template variables. Add alerting rules with severity labels. Use OpenTelemetry for trace collection. Forward logs to Loki or Elasticsearch. Connect to Jaeger or Tempo for tracing. Monitor metrics, logs, and traces together.
Container & Docker Safety
Dockerfiles use multi-stage builds for small images. Base images are pinned to exact versions. Dev files are excluded from final images. Health checks are added for orchestrator use. Containers switch to non-root users. Docker Compose uses named volumes and networks. Resource limits are set in deploy configs.
Multiple Output Formats
Export as YAML, JSON, HCL, or TOML. Kubernetes uses YAML with proper separators. Terraform uses HCL with correct escaping. JSON output has consistent indentation. Copy to clipboard with one click. Preview output with syntax highlighting. Line numbers help you review quickly.