Open Source CLI + Web Tool

Mask your .env files
across machines

Built for your environment backups and best practices. Securely share configuration files
via screenshots, Slack messages, and team wikis – without exposing secrets.

terminal
# Install via npm
$ npm install -g dotsnap

# Run in your project directory
$ dotsnap mask

✓ Found .env file
✓ Masked 8 secrets
✓ Saved to .env.safe

# Or use the web UI
$ dotsnap web

Three ways to use DotSnap

Choose the method that works best for your workflow

CLI Tool

Install globally and use from any project directory

npm install -g dotsnap
  • Auto-detects .env files
  • Saves .env.safe locally
  • Works offline

NPX (No Install)

Run directly without installing anything

npx dotsnap mask
  • No global installation
  • Always latest version
  • Perfect for CI/CD

Web UI

Browser-based tool for quick masking

  • No installation needed
  • 100% client-side
  • Share via link

Built for developers who care about security

CLI & web UI options. Works with any workflow. No vendor lock-in.

Client-Side Processing

All masking happens locally. Your secrets never touch our servers or leave your machine.

Smart Detection

Automatically identifies and highlights risky keys like tokens, passwords, and API credentials.

Preserve Context

Shows first and last characters so you can identify which credential is which.

Format Preserving

Maintains comments, empty lines, and structure. Your .env.safe file looks just like the original.

Instant Results

Lightning-fast masking with copy, download, and shareable link capabilities built-in.

Team Friendly

Share configs safely in Slack, screenshots, wikis, or documentation without worry.

Security by design

Your environment variables NEVER leave your computer. We built it with trust in mind.

What's Protected

  • ✓Securely masks tokens before sharing
  • ✓100% client-side processing (web & CLI)
  • ✓No external API calls or network requests
  • ✓No backend, no cloud storage, no logging
  • ✓Original .env stays untouched on your machine
  • ✓Open source - audit the code yourself

What's NOT Protected

  • ✗Can't prevent malicious local scripts
  • ✗Masked values still show partial info
  • ✗Original file remains on file system
  • ✗Screenshots may still capture context