Quickstart Guide
This guide walks you through installingenvtrap, running it against your application, understanding its output, and integrating it into your deployment workflow.
Prerequisites
- Node.js:
18.0.0or higher (ESM customization hooks require Node.js 18+). - Package Manager:
npm,pnpm, oryarn.
Getting Started
1
Install envtrap
Install envtrap globally, locally as a dev dependency, or execute it on-demand via
npx:- Global (Recommended)
- pnpm
- npm (Dev Dependency)
- npx (No Install)
2
Run your application with envtrap
Simply prefix your standard startup command with
envtrap run:envtrap forwards all process arguments, environment variables, exit codes, and signals (SIGINT, SIGTERM) directly to and from your application.3
Review the startup banner
When
envtrap starts, it reads available secrets from process.env and your .env file, spins up the in-memory MITM proxy, and outputs a configuration overview to standard error:4
Simulate or observe an interception
If any dependency or script attempts to transmit credentials over an unapproved channel, envtrap immediately intercepts the operation and logs a structured alert box:
Notice that the actual secret value is never printed in plain text. It is automatically replaced with a non-reversible SHA-256 fingerprint prefix, protecting your credentials even if logs are ingested into public CI/CD pipelines or cloud dashboards.
5
Inspect the exit summary
When your application terminates, envtrap prints a grouped summary of all monitored events and writes an incident audit report to
.envtrap-report.json:Adding to package.json
To make envtrap a standard part of your development and production lifecycle, wrap your npm scripts in package.json:
package.json
Next Steps
Configuration Reference
Learn how to configure channel modes, exclude trusted domains, and set custom entropy levels.
CLI Reference
Explore all CLI flags including
--env-file, --no-mitm, --verbose, and --log-file.