Exclusions & Allowlisting
In production applications, certain outbound operations are legitimate — such as sending your Stripe API key toapi.stripe.com or printing mock test tokens in unit test suites.
envtrap provides two powerful exclusion mechanisms in envtrap.json:
- Domain Allowlisting (
exclusions.domains): Bypasses network proxy inspection for trusted hosts. - Path Glob Exclusions (
exclusions.paths): Suppresses alerts from designated source files or directories.
1. Domain Exclusions (exclusions.domains)
- Applies To: The
networkchannel. - Mechanism: Exact hostname matching and automatic
NO_PROXYinclusion.
exclusions.domains are granted direct pass-through status:
- HTTPS/HTTP requests to these hosts are not decrypted or scanned.
- Hosts are automatically appended to the child process’s
NO_PROXYenvironment variable, avoiding unnecessary proxy hops.
envtrap.json
2. Path Glob Exclusions (exclusions.paths)
- Applies To:
stdout,stderr,child_process, anddns. - Mechanism: Call stack frame inspection and child-level pre-redaction.
envtrap analyzes the originating call stack. If the calling source file matches any glob pattern in exclusions.paths, the alert is suppressed.
envtrap.json
Glob Matching Syntax:
Patterns that do not begin with
/ or ** are automatically prepended with **/ so they match files anywhere in your project tree.Combined Production Configuration
Here is a recommended setup for an Express or Next.js application that integrates with external payment and AI APIs while running automated test suites:envtrap.json
