Loading...
Ababil Hossain
Ababil Hossain

Self-taught Software Developer | Full-Stack, DevTools & Open Source

EnvLink - Secure and Anonymous ENV File Sharing

EnvLink - Secure and Anonymous ENV File Sharing

Share .env files securely with team members using encryption and automatic expiration.

If you’ve worked on a dev team, you know the drill: someone needs your.envfile, and you’re stuck wondering if you should really send it over Slack or Discord. Spoiler alert—you probably shouldn’t. That’s where EnvLink comes in.

It’s an open-source CLI tool I built to solve exactly this problem. Share.envfiles securely with end-to-end encryption, optional password protection, and automatic expiration. Best part? No signup, no account creation, completely anonymous. Just install and go.

What You Get

Two Ways to Share

EnvLink gives you two security models depending on your needs.

Password-Protected is for the serious stuff—production keys, database credentials, anything you’d lose sleep over if it leaked. This mode uses zero-knowledge security, meaning the server literally cannot decrypt your data even if it wanted to. You set custom expiration (anything from 30 minutes to never), and you can update the link later if needed.

Optional-Password (the default) is perfect when you just need to quickly share something with a teammate. No password hassle, just a single ID to copy-paste. It expires after one hour automatically, which is usually enough for onboarding or quick setups.

Strong Encryption Under the Hood

EnvLink uses AES-256-GCM encryption with PBKDF2 key derivation (100,000 iterations, if you’re curious). All encryption happens client-side before anything touches the server. Each EnvLink gets a unique salt and IV. The technical bits are solid, so you can focus on your work instead of worrying about security.

Share Multiple Files at Once

Sometimes it’s not just.env—you’ve got.env.local,.env.production,.env.staging, maybe more. EnvLink lets you bundle up to 10 files in one go. Pretty convenient when setting up a new teammate.

Expiration on Your Terms

With password-protected links, you choose how long they last:

  • 30mfor urgent, short-term sharing
  • 24hfor a day
  • 5dwhen you need a few days
  • 6Mfor long-running projects
  • 1yfor a full year
  • neverif you want it permanent (though I’d recommend thinking twice about that one)

Getting Started

Install It Globally

If you’ll use it regularly, install it once:

BASH
npm install -g envlink

Or Run It Without Installing

Prefer not to install? No problem—just usenpxor your favorite package runner:

BASH
# Node.js
npx envlink create
npx envlink install el_abc123xyz456accesskey789

# Bun
bunx envlink create

# pnpm
pnpm dlx envlink create

How to Use It

Quick Sharing (No Password)

Say you need to onboard a new developer fast. You don’t want the password dance. Here’s what you do:

Create the EnvLink:

BASH
cd my-project
envlink create

You’ll see something like:

TEXT
✓ EnvLink Created Successfully!

ID: el_abc123xyz456accesskey789
Expiry: 1 hour (fixed)
Files: .env

Share this ID to install the files.

Send that ID to your teammate. They install it with:

BASH
envlink install el_abc123xyz456accesskey789

Done. No password needed. It vanishes in an hour automatically.

Secure Sharing (With Password)

For production credentials or anything sensitive, add a password:

BASH
cd my-project
envlink create --pass yourpassword --exp 7d --ref "production-keys"

The--exp 7dmeans it expires in 7 days. The--reftag is just a label so you remember what it’s for later.

Your teammate installs it like this:

BASH
envlink install el_abc123xyz456 --pass yourpassword

Pro tip: send the password through a different channel—maybe a phone call or Signal message. Defense in depth and all that.

Want to see when something expires or what files are in it?

BASH
# Optional-password (no password needed)
envlink info el_abc123xyz456accesskey789

# Password-protected (password required)
envlink info el_abc123xyz456 --pass yourpassword

Only password-protected EnvLinks can be updated:

BASH
# Update the files
envlink update el_abc123xyz456 --files --current-pass yourpassword

# Extend expiration
envlink update el_abc123xyz456 --exp 30d --current-pass yourpassword

# Change the password
envlink update el_abc123xyz456 --pass newpassword --current-pass yourpassword

Manually Delete It

Finished early? Kill it manually:

BASH
# Optional-password
envlink expire el_abc123xyz456accesskey789

# Password-protected
envlink expire el_abc123xyz456 --pass yourpassword

A Few Handy Extras

Pick and Choose Files

If an EnvLink has multiple files but you only need some of them:

BASH
envlink install el_abc123xyz456 --select-files

You’ll get an interactive menu where you can check off exactly what you want. Saves time when you’re only working on staging and don’t need the production config cluttering things up.

Reference Labels

When you’re juggling multiple EnvLinks, labels help you keep track:

BASH
envlink create --pass mypass --ref "staging-database-credentials"
envlink create --pass mypass --ref "production-api-keys"

Future you will thank you for this.

Check for Updates

BASH
envlink version-check
# or
envlink check-update

How the Security Actually Works

People always ask: “Can the server see my stuff?” Short answer: No.

Password-Protected Mode

Here’s what happens when you create a password-protected EnvLink:

  1. Your password gets hashed with SHA-256
  2. PBKDF2 (with 100,000 iterations) generates the encryption key
  3. Your files get encrypted on your machine with AES-256-GCM
  4. Zero-knowledge proof authentication validates everything

The server stores the encrypted data, salt, IV, and a password hash—but never your actual password, never the encryption key, and never your decrypted files. The server physically cannot decrypt your data. Even if someone hacked the server, all they’d get is encrypted gibberish.

Optional-Password Mode

This one’s equally secure, just simpler:

  1. An access key is generated locally on your machine
  2. Everything gets encrypted client-side with AES-256-GCM
  3. The access key never leaves your computer
  4. It’s embedded in the extended ID you share

The server only receives the base ID and encrypted data. Without the access key (which it never has), decryption is impossible.

Password-Protected vs Optional-Password

FeaturePassword-ProtectedOptional-Password
Password requiredYesNo
Can the server decrypt it?No (zero-knowledge)No (zero-knowledge)
ID formatel_abc123xyz456el_abc123xyz456accesskey789
ExpirationFlexible, including neverFixed at 1 hour
Update supportYesNo
Best forSensitive data and team sharingConvenient temporary sharing

When to Use Which

FeaturePassword-ProtectedOptional-Password
Password requiredYesNo
Can server decrypt?No (zero-knowledge)No (zero-knowledge)
ID formatel_abc123xyz456(19 chars)el_abc123xyz456accesskey789(35 chars)
ExpirationFlexible (30m to never)Fixed at 1 hour
Update supportYesNo
Best forSensitive production data, long-term sharingQuick onboarding, temporary sharing

Real-World Examples

Onboarding a New Developer

New teammate joins, needs to get set up quickly:

BASH
# You create the link (no password, fast)
envlink create

# They install it
envlink install el_abc123xyz456accesskey789

# Gone in an hour—no cleanup needed

Sharing Production Credentials

You’re giving someone access to production API keys or database credentials:

BASH
# Create with password and 7-day expiration
envlink create --pass SecureP@ss123 --exp 7d --ref "production-api-keys"

# They install it
envlink install el_abc123xyz456 --pass SecureP@ss123

# Auto-deletes after a week

Staging Environment Setup

Working on staging for a day or two:

BASH
# 24-hour EnvLink for staging
envlink create --pass staging123 --exp 24h --ref "staging-env"

# Update it if needed
envlink update el_abc123xyz456 --files --current-pass staging123

# Delete manually when done
envlink expire el_abc123xyz456 --pass staging123

Limitations to Know

EnvLink is powerful, but there are some sensible limits:

  • File count: Max 10.envfiles per EnvLink
  • File size: Each file can be up to 100KB
  • Total payload: All files combined can’t exceed 500KB
  • File naming: Files must follow.envor.env.{suffix}pattern

These limits are pretty generous for most use cases. If you’ve got a massive.envfile, you might want to think about breaking it up anyway.

Why I Built This

I got tired of the anxiety around sharing.envfiles. You know that feeling—you send it over Slack, then realize it’s sitting there in the chat history forever. Or you paste it into a “secure” shared document that… isn’t really that secure.

What I like most about EnvLink:

  • No account needed. Seriously. No email, no verification, no tracking. Install it and use it.

  • Two modes for different situations. Need speed? Use optional-password. Need serious security? Add a password. Your choice.

  • Auto-expiration. This might be my favorite feature. You don’t have to remember to clean up. Set it and forget it—the link destroys itself.

  • Actually private. Zero-knowledge encryption means I can’t see your data even if I wanted to. And I don’t want to.

Common Questions

Can the server really not see my data?

Really. Both modes use zero-knowledge security. Password-protected uses ZK-proof authentication. Optional-password never sends the access key to the server. Even if someone compromised the server, your data stays encrypted.

Which mode should I use?

Depends on your situation:

  • Quick sharing with teammates who just need to get set up? → Optional-password
  • Production credentials or anything that’d cause problems if leaked? → Password-protected

Can I recover an expired EnvLink?

Nope. When it expires, it’s permanently deleted. This is intentional—you don’t want old credentials lingering around, even encrypted.

How many files can I share?

Up to 10.envfiles in one EnvLink. That’s usually way more than you need, but it’s there if you need it.

Wrapping Up

Sharing.envfiles is something every dev team deals with, but most teams don’t do it securely. EnvLink gives you a simple, practical way to fix that without adding friction to your workflow.

If you’re regularly sharing environment variables with your team, give EnvLink a shot. It’s made the process cleaner and less stressful for me, and I think it’ll do the same for you.


Links:

Install it now:

BASH
npm install -g envlink

Stay secure out there. 🔐

Advertisement

Join the conversation

Share your thoughts

Loading comments...
Reading Progress 0%

Share this post