Skip to main content

pv-dotenv

Drop-in replacement for python-dotenv that resolves psamvault: placeholders at runtime.

Keep your .env files safe from AI agents. The agent sees only placeholders. Your app gets the real secrets.

Why?

# Before: secrets in plaintext — any agent reading .env can see them
DATABASE_URL=postgresql://user:password@neon.tech/db
JWT_SECRET=your-secret-key

# After: placeholders — agent sees nothing, app resolves at runtime
DATABASE_URL=psamvault:DATABASE_URL
JWT_SECRET=psamvault:JWT_SECRET

Installation

pip install pv-dotenv

Quick Start

Replace your existing dotenv import:

# Before (python-dotenv):
from dotenv import load_dotenv
load_dotenv()

# After (pv-dotenv):
from pv_dotenv import load_dotenv
load_dotenv()

Everything else stays the same. Your code reads from os.environ exactly as before.

With project scoping

If you used scan_and_protect(project_name="my-project"), pass the same name:

load_dotenv(project_name="my-project")

Without modifying os.environ

from pv_dotenv import resolve_dotenv

values = resolve_dotenv()
# → {"DATABASE_URL": "postgresql://...", "JWT_SECRET": "..."}

Override existing env vars

By default, existing environment variables are not overwritten. To force override:

load_dotenv(override=True)

How It Works

  1. Reads your .env file (or custom path)
  2. For each psamvault:KEY value:
    • Fetches the encrypted blob from the psamvault backend
    • Decrypts it locally using your Vault Encryption Key (VEK)
    • Sets os.environ[KEY] to the real value
  3. Non-psamvault: values (like NODE_ENV=production) pass through unchanged

Auth

Path Source Works Where
A: OS Keychain psamvault login Your dev machine
B: Env Vars PSAMVAULT_VEK + PSAMVAULT_TOKEN Docker, CI, servers

Path A requires no setup beyond psamvault login. Path B is for environments without a keychain (Docker, CI, servers).

Prerequisites

  • Python 3.10+
  • A psamvault account — pipx install psamvault and psamvault login

Development

# Install dev dependencies
pip install -e ".[dev]"

# Run tests
pytest

Related

Package What It Does
psamvault-cli CLI + MCP server — manage your vault
pv-dotenv SDK — resolve placeholders at runtime

Metadata

Release files for pv-dotenv 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pv-dotenv 0.1.0
File Size Uploaded
pv_dotenv-0.1.0.tar.gz 9.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pv-dotenv 0.1.0
File Interpreter ABI Platform
pv_dotenv-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 17.3 kB

Release files / pv_dotenv-0.1.0.tar.gz

Download URL pv_dotenv-0.1.0.tar.gz
Size 9.9 kB
Tags Source
SHA-256 checksum
How to use checksums
cd971120a6fdc999d8f2618dc7309c9e26962d588c8ee648db34206460f9e2d6
BLAKE2b-256 checksum
How to use checksums
a180deb7b88dd01885d21cce247e8757be28e0fa421458591462fc6397edfabc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release files / pv_dotenv-0.1.0-py3-none-any.whl

Download URL pv_dotenv-0.1.0-py3-none-any.whl
Size 7.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
541c4611df871b8eeb4b1628a2f3de978d78a1d5d8f9736aa05b04541141a37b
BLAKE2b-256 checksum
How to use checksums
f7a6a86de4f18d540ad24a4308829f8667d15867c6576e77017133af08fb9778
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.0

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page