The Krypt Blog
Engineering notes, security deep-dives, and product updates from the team building Krypt.
Featured·
What Is Secrets Management? A Practical Guide for Small Teams
Secrets management is how a team stores, shares and controls access to credentials like API keys and database passwords. What it means, why .env files stop working, how it works in practice, and what a team of 2 to 20 actually needs.
Read post →
Featured·
Best Secrets Management Tools for Small Dev Teams (2026)
Nine secrets managers compared for teams of 2 to 20: Doppler, Infisical, Vault, AWS, 1Password, Bitwarden, Krypt and more. Pricing model, hosting, setup effort, and which to pick.
Read post →
Featured·
Doppler Alternatives for Small Dev Teams (2026)
Six Doppler alternatives compared on pricing model, hosting, and setup effort. Which secrets manager fits a team of 2 to 20, and when Doppler is still the right call.
Read post →
Featured·
What Is a .env File (and How to Use One Properly)
A .env file stores your app's configuration and secrets outside your code. How the format works, how to load it in Node, Python and Docker, and the mistakes that leak keys.
Read post →
All posts
AI Coding Tools and .env File Exposure: What Actually Gets Sent
Cursor, Copilot and Claude Code all read your project files. What each one does with .env by default, how to check, how to exclude them, and why ignore files are not a security boundary.
Read →
AWS Secrets Manager Pricing Explained (With Real Cost Examples)
AWS Secrets Manager costs $0.40 per secret per month plus $0.05 per 10,000 API calls. What that works out to in practice, the costs people miss, how it compares to Parameter Store, and when it is the wrong tool.
Read →
HashiCorp Vault Pricing: What It Actually Costs to Run
Vault Community is free but not free to operate. What HCP Vault Dedicated costs, what changed with the BSL licence and IBM acquisition, the real cost of self-hosting, and when a small team should not use Vault at all.
Read →
OWASP Secrets Management Cheat Sheet, Explained for Small Teams
The OWASP Secrets Management Cheat Sheet in plain English, with a checklist of which recommendations actually apply to a team of 2 to 20 and which are written for organisations with a platform team.
Read →
Heroku Environment Variables: How to Set, Check and Manage Config Vars
Heroku calls environment variables config vars. How to check them, set them from the CLI and dashboard, use them in your app, keep them in sync across staging and production, and what Heroku does not do for you.
Read →
How to Inject Environment Variables into the Build Process
Inject environment variables into builds in Jenkins, GitHub Actions, Docker and frontend bundlers. Build time vs runtime, where secrets should come from, and the mistakes that bake credentials into images.
Read →
ModuleNotFoundError: No module named 'dotenv' (How to Fix)
The dotenv module is called python-dotenv on pip, not dotenv. Every cause of this error and the one-line fix for each, including virtual environments, wrong Python versions, and the wrong package installed.
Read →
python-dotenv: The Complete Guide to load_dotenv and .env Files in Python
How python-dotenv works: install, load_dotenv, dotenv_values, override behaviour, variable expansion, multiline values, framework setup for Django, Flask and FastAPI, and when not to use it.
Read →
Docker Compose Environment Variables: .env vs env_file Explained
Docker Compose has two different .env mechanisms that do different things. How each one works, the precedence order when they conflict, default and required variable syntax, and how to debug what a container actually received.
Read →
Python Environment Variables: How to Get, Set and Load Them
Read environment variables with os.environ, set them for a process, load them from a .env file with python-dotenv, and avoid the string-type trap that breaks most first attempts.
Read →
Introducing the Krypt blog
Why we're writing about secrets management, what to expect from this blog, and where Krypt is headed.
Read →