Skip to main content

Quickstart Guide

This guide walks you through installing envtrap, running it against your application, understanding its output, and integrating it into your deployment workflow.

Prerequisites

  • Node.js: 18.0.0 or higher (ESM customization hooks require Node.js 18+).
  • Package Manager: npm, pnpm, or yarn.

Getting Started

1

Install envtrap

Install envtrap globally, locally as a dev dependency, or execute it on-demand via npx:
2

Run your application with envtrap

Simply prefix your standard startup command with envtrap run:
envtrap forwards all process arguments, environment variables, exit codes, and signals (SIGINT, SIGTERM) directly to and from your application.
3

Review the startup banner

When envtrap starts, it reads available secrets from process.env and your .env file, spins up the in-memory MITM proxy, and outputs a configuration overview to standard error:
4

Simulate or observe an interception

If any dependency or script attempts to transmit credentials over an unapproved channel, envtrap immediately intercepts the operation and logs a structured alert box:
Notice that the actual secret value is never printed in plain text. It is automatically replaced with a non-reversible SHA-256 fingerprint prefix, protecting your credentials even if logs are ingested into public CI/CD pipelines or cloud dashboards.
5

Inspect the exit summary

When your application terminates, envtrap prints a grouped summary of all monitored events and writes an incident audit report to .envtrap-report.json:

Adding to package.json

To make envtrap a standard part of your development and production lifecycle, wrap your npm scripts in package.json:
package.json

Next Steps

Configuration Reference

Learn how to configure channel modes, exclude trusted domains, and set custom entropy levels.

CLI Reference

Explore all CLI flags including --env-file, --no-mitm, --verbose, and --log-file.