Hush by Umikflow
← Back to Blog
Developer Security6 min read•By Umikflow

How to Share .env Files Without Exposing Secrets

Learn how to securely transmit environment variables to developers without compromising infrastructure.

The Sensitivity of .env Files

In modern web development, `.env` files contain environment variables required to run an application. These files typically store highly sensitive information, such as database connection strings, third-party API keys, and secret salts for cryptographic hashing.

Because of the high-value credentials they contain, `.env` files should never be committed to Git. A single accidental commit to a public repository can result in exposed databases, compromised cloud infrastructure, and massive financial liability.

Secrets Management vs. Transmission

When working with a team, you need a way to distribute environment variables. It is crucial to distinguish between long-term secrets management and one-time transmission.

For long-term storage and synchronization across a team or CI/CD pipelines, you should use dedicated secrets managers (like AWS Secrets Manager, Doppler, or HashiCorp Vault).

However, you may sometimes need to temporarily hand over a specific configuration to a contractor or a new developer before they are onboarded into the primary system. This is a transmission problem.

Practical Transmission Checklist

When you must transmit environment variables, avoid sending them directly through Slack or email, where they sit indefinitely in chat history. Instead, follow this secure handoff checklist:

  1. Remove Unnecessary Values: Never send the production `.env` file. Strip out any credentials the developer doesn't strictly need to run the application locally.
  2. Scope and Rotate: Generate temporary, limited-scope API keys specifically for local development.
  3. Use a Short Expiry: Use a tool like Hush to generate a one-time secret link with an explicit, short expiration time.
  4. Confirm Receipt: Send the link and confirm through a separate channel (Out-of-Band sharing) that the recipient successfully retrieved the file.
  5. Revoke and Rotate: If the developer leaves the project, immediately rotate any credentials they had access to.

Hush as a Transmission Tool

Hush is designed for the temporary transmission of sensitive data. It is not a secret manager, nor a source-control replacement. By encrypting the `.env` contents in the browser and consuming the payload upon access, Hush ensures that the configuration does not persist in email or chat logs.

For more details on how Hush works, read about our Security Model and How it Works or our guide on securely sharing API keys.

Frequently Asked Questions

Can I use Hush to store my production .env file?
No. Hush is a temporary transmission tool. Use a dedicated secrets manager for long-term storage and CI/CD integration.

Need to share a secret securely?

Hush encrypts your data in the browser before sending it.

Create a Hush Secret