# envtrap - [Introduction](https://envtrap.vercel.app/docs/introduction.md): Zero-configuration runtime secret leak detector and egress firewall for Node.js 18+. - [Quickstart](https://envtrap.vercel.app/docs/quickstart.md): Get envtrap v3.1 protecting your Node.js application in under 60 seconds. - [Framework Guides](https://envtrap.vercel.app/docs/frameworks.md): How to run envtrap with Express, NestJS, Next.js, Fastify, and Docker containers. - [MCP Server Integration](https://envtrap.vercel.app/docs/mcp-server.md): Connect Cursor, Claude Desktop, Antigravity, and AI agents directly to the EnvTrap Model Context Protocol (MCP) server. - [Process Architecture](https://envtrap.vercel.app/docs/how-it-works/architecture.md): The two-tier process boundary between the envtrap CLI parent and the monitored child application. - [In-Memory MITM Proxy](https://envtrap.vercel.app/docs/how-it-works/mitm-proxy.md): How envtrap decrypts, inspects, and blocks outbound HTTPS and HTTP egress traffic using an in-memory loopback TLS proxy. - [Runtime Module Hooks](https://envtrap.vercel.app/docs/how-it-works/module-hooks.md): How envtrap intercepts node:child_process and node:dns across both ESM and CommonJS modules. - [Secret Detection Engine](https://envtrap.vercel.app/docs/how-it-works/secret-detection.md): How envtrap loads secrets from the environment, evaluates entropy, and matches exfiltration attempts at runtime. - [Live Secret Synchronization](https://envtrap.vercel.app/docs/how-it-works/live-sync.md): How envtrap syncs dynamically-rotated credentials from process.env to the ESM loader thread in real time. - [Channels Overview](https://envtrap.vercel.app/docs/channels/overview.md): Understanding envtrap's five egress monitoring channels and their enforcement modes. - [Network Channel](https://envtrap.vercel.app/docs/channels/network.md): In-depth guide to inspecting and blocking outbound HTTP and HTTPS requests with the network channel. - [DNS Channel](https://envtrap.vercel.app/docs/channels/dns.md): How envtrap intercepts node:dns resolution calls to stop secret leaks and DNS tunneling exfiltration. - [Subprocess Channel](https://envtrap.vercel.app/docs/channels/child-process.md): How envtrap monitors node:child_process to prevent credential leakage into subprocess environments. - [Terminal Streams Channel](https://envtrap.vercel.app/docs/channels/stdio.md): How envtrap scans and redacts secrets from stdout and stderr console streams in real time. - [envtrap.json Configuration](https://envtrap.vercel.app/docs/configuration/envtrap-json.md): Complete schema specification, default values, and validation rules for envtrap.json. - [Exclusions & Whitelisting](https://envtrap.vercel.app/docs/configuration/exclusions.md): Configure trusted domain allowlists and source file glob exclusions to eliminate false positives. - [Configuration Recipes](https://envtrap.vercel.app/docs/configuration/recipes.md): Battle-tested configuration templates for production, local development, and CI/CD pipelines. - [Threat Vectors & Supply Chain Attacks](https://envtrap.vercel.app/docs/security/threat-vectors.md): Understanding how compromised packages, malicious updates, and diagnostic SDKs exfiltrate credentials. - [AI-Safe Design & Redaction](https://envtrap.vercel.app/docs/security/ai-safe-design.md): How envtrap protects credentials from leaking into AI assistants, log aggregators, and LLM agent pipelines. - [Incident Reports & Auditing](https://envtrap.vercel.app/docs/security/reports.md): Understanding .envtrap-report.json, streaming JSONL audit events, and responsible vulnerability disclosure. - [Vulnerability Disclosure](https://envtrap.vercel.app/docs/security/disclosure.md): How to responsibly disclose security vulnerabilities and bypasses found in envtrap. - [envtrap run](https://envtrap.vercel.app/docs/cli/run.md): Reference for the envtrap run command, arguments, and execution flags. - [envtrap check](https://envtrap.vercel.app/docs/cli/check.md): Validate envtrap.json syntax and configuration rules before deployment. - [Exit Codes & Signals](https://envtrap.vercel.app/docs/cli/exit-codes.md): How envtrap handles process exit codes, Unix signals, and error states. - [Changelog](https://envtrap.vercel.app/docs/changelog.md): Release history and migration guides for envtrap. - [Developer & Contributing Guide](https://envtrap.vercel.app/docs/development.md): Setting up the development environment, running unit tests, and understanding the Clean Architecture design. - [Introduction](https://envtrap.vercel.app/docs/introduction.md): Zero-configuration runtime secret leak detector and egress firewall for Node.js 18+. - [Quickstart](https://envtrap.vercel.app/docs/quickstart.md): Get envtrap v3.1 protecting your Node.js application in under 60 seconds. - [Framework Guides](https://envtrap.vercel.app/docs/frameworks.md): How to run envtrap with Express, NestJS, Next.js, Fastify, and Docker containers. - [MCP Server Integration](https://envtrap.vercel.app/docs/mcp-server.md): Connect Cursor, Claude Desktop, Antigravity, and AI agents directly to the EnvTrap Model Context Protocol (MCP) server. - [Process Architecture](https://envtrap.vercel.app/docs/how-it-works/architecture.md): The two-tier process boundary between the envtrap CLI parent and the monitored child application. - [In-Memory MITM Proxy](https://envtrap.vercel.app/docs/how-it-works/mitm-proxy.md): How envtrap decrypts, inspects, and blocks outbound HTTPS and HTTP egress traffic using an in-memory loopback TLS proxy. - [Runtime Module Hooks](https://envtrap.vercel.app/docs/how-it-works/module-hooks.md): How envtrap intercepts node:child_process and node:dns across both ESM and CommonJS modules. - [Secret Detection Engine](https://envtrap.vercel.app/docs/how-it-works/secret-detection.md): How envtrap loads secrets from the environment, evaluates entropy, and matches exfiltration attempts at runtime. - [Live Secret Synchronization](https://envtrap.vercel.app/docs/how-it-works/live-sync.md): How envtrap syncs dynamically-rotated credentials from process.env to the ESM loader thread in real time. - [Channels Overview](https://envtrap.vercel.app/docs/channels/overview.md): Understanding envtrap's five egress monitoring channels and their enforcement modes. - [Network Channel](https://envtrap.vercel.app/docs/channels/network.md): In-depth guide to inspecting and blocking outbound HTTP and HTTPS requests with the network channel. - [DNS Channel](https://envtrap.vercel.app/docs/channels/dns.md): How envtrap intercepts node:dns resolution calls to stop secret leaks and DNS tunneling exfiltration. - [Subprocess Channel](https://envtrap.vercel.app/docs/channels/child-process.md): How envtrap monitors node:child_process to prevent credential leakage into subprocess environments. - [Terminal Streams Channel](https://envtrap.vercel.app/docs/channels/stdio.md): How envtrap scans and redacts secrets from stdout and stderr console streams in real time. - [envtrap.json Configuration](https://envtrap.vercel.app/docs/configuration/envtrap-json.md): Complete schema specification, default values, and validation rules for envtrap.json. - [Exclusions & Whitelisting](https://envtrap.vercel.app/docs/configuration/exclusions.md): Configure trusted domain allowlists and source file glob exclusions to eliminate false positives. - [Configuration Recipes](https://envtrap.vercel.app/docs/configuration/recipes.md): Battle-tested configuration templates for production, local development, and CI/CD pipelines. - [Threat Vectors & Supply Chain Attacks](https://envtrap.vercel.app/docs/security/threat-vectors.md): Understanding how compromised packages, malicious updates, and diagnostic SDKs exfiltrate credentials. - [AI-Safe Design & Redaction](https://envtrap.vercel.app/docs/security/ai-safe-design.md): How envtrap protects credentials from leaking into AI assistants, log aggregators, and LLM agent pipelines. - [Incident Reports & Auditing](https://envtrap.vercel.app/docs/security/reports.md): Understanding .envtrap-report.json, streaming JSONL audit events, and responsible vulnerability disclosure. - [Vulnerability Disclosure](https://envtrap.vercel.app/docs/security/disclosure.md): How to responsibly disclose security vulnerabilities and bypasses found in envtrap. - [envtrap run](https://envtrap.vercel.app/docs/cli/run.md): Reference for the envtrap run command, arguments, and execution flags. - [envtrap check](https://envtrap.vercel.app/docs/cli/check.md): Validate envtrap.json syntax and configuration rules before deployment. - [Exit Codes & Signals](https://envtrap.vercel.app/docs/cli/exit-codes.md): How envtrap handles process exit codes, Unix signals, and error states. - [Developer & Contributing Guide](https://envtrap.vercel.app/docs/development.md): Setting up the development environment, running unit tests, and understanding the Clean Architecture design. This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.