Sotto

Share .env files without the screenshot dance.

Your .env holds every key your app needs, and today it travels by screenshot, Slack paste, or shoulder surf. Import it into Sotto and share it with your team encrypted end to end.

From file to shared vault

  1. Import what you have. sotto import .env encrypts every value locally. The file itself never leaves your machine.
  2. Grant your team. Teammates get access through cryptography, not a permission bit. They decrypt on their own machines.
  3. Stay in sync. Change a value in one place, push, and teammates get it on their next pull. Remove someone and the keys rotate away from them.
$ sotto import .env
imported 14 secret(s) into acme-api (dev)
$ sotto push
pushed acme-api/dev - revision 1

Questions, answered

Do I have to delete my .env file?

No. Sotto reads it and encrypts the values into your vault. Keep the file, gitignore it, or delete it - your call.

How do teammates get updates?

They pull. Changed values sync as ciphertext and decrypt on their machines with their own grant.

What if someone leaves the team?

Remove them and Sotto rotates the affected keys, so their old grants decrypt nothing going forward.

One vault, whole team

Free for teams of up to three, with one shared project. Import your .env in under a minute.