The options
.env files
Plain key=value files loaded into the process environment.
Solo developers and small local projects where simplicity beats ceremony and secrets never leave the machine. Never commit the file.
Managed vault (Doppler, AWS Secrets Manager, GCP)
A hosted service that centralizes secrets and injects them at runtime.
Teams that want rotation, audit logs, and per-environment config without running their own infrastructure.
HashiCorp Vault
A self-hosted secrets and encryption platform with dynamic secrets.
Security-conscious or regulated organizations that need fine-grained policies, dynamic short-lived secrets, and full control on their own hardware or cloud.
Team password manager (1Password, Bitwarden)
A shared vault with a CLI and secrets-injection for smaller teams.
Small teams who already share logins and want one tool for both human credentials and machine secrets, with low operational overhead.
Which one fits you?
Answer a few questions to get a recommendation.
Question 1 of 4