Skip to main content

envtrap.json Configuration Reference

Configure envtrap by placing an envtrap.json file in your project root (adjacent to package.json). All configuration options are optional. When a field is omitted, envtrap applies safe, production-grade defaults automatically.

Complete Schema & Defaults

envtrap.json

Schema Properties

channels

  • Type: object
  • Default: See schema above
Controls the enforcement mode for each of the five runtime egress channels. Each channel accepts one of three valid modes:
  • "block": Prevent the leak. Network sockets are severed, DNS and child process calls throw errors, and stdout/stderr leaks kill the process with SIGTERM.
  • "warn": Log the alert box, redact the secret value with its SHA-256 fingerprint, and allow execution to continue.
  • "off": Completely disable monitoring for this channel.

exclusions

  • Type: object
Bypasses monitoring for trusted third-party endpoints or specific source files.

exclusions.domains

  • Type: string[]
  • Default: []
A list of trusted domain names that are permitted to receive outbound traffic containing credentials. Connections to these domains bypass proxy inspection and are automatically appended to NO_PROXY.

exclusions.paths

  • Type: string[]
  • Default: []
A list of file glob patterns. Output originating from matching source files is pre-redacted inside the child process, suppressing alerts in the parent scanner. Ideal for test runners or seed scripts.

entropy

  • Type: object
Configures the statistical threshold for the candidate secret filter.

quiet

  • Type: boolean
  • Default: false
When set to true, suppresses the startup banner and immediate per-leak terminal alerts. The final exit summary and report files are still generated.

logFile

  • Type: string | null
  • Default: null
A file path where envtrap streams structured JSONL events as leaks occur. Can be relative to CWD or an absolute path.

Configuration Recipes

Blocks all network leaks, DNS tunneling, and subprocess leaks:

Validating Your Configuration

Run envtrap check to validate your envtrap.json file against the schema before running your application:
Output: