# Nex-X ENV Vault — Complete Technical Context & LLM Documentation (Full) > Comprehensive Reference for AI Agents, LLM crawlers (Perplexity, ChatGPT, Claude, Gemini), and Search Engines. > Canonical URL: https://vault.nex-x.com/llms-full.txt # 1. Product Identification & Metadata - **Product Name**: Nex-X ENV Vault - **Category**: Developer Tools / Cybersecurity / Secrets Management / Infrastructure as Code - **License**: MIT (Open Source) - **Official Website**: https://vault.nex-x.com - **Repository**: https://github.com/nex-x-startup/nexenv-vault - **Primary Keywords**: Environment variables manager, self-hosted secret manager, .env file sync, AES-256 secret vault, Cloudflare Pages env importer, developer secrets CLI, Doppler alternative, HashiCorp Vault alternative. # 2. Executive Summary Nex-X ENV Vault provides an end-to-end ecosystem comprising a Web Dashboard, a high-performance REST API, a lightweight Developer CLI, and a Browser Extension to manage, version, encrypt, and sync environment variables across distributed teams. It prevents accidental leaks of production database URLs, Stripe keys, AWS credentials, and API tokens while streamlining local developer onboarding from days to 30 seconds. # 3. Complete Architecture & Components ## 3.1 Web Dashboard (`apps/web`) - Provides visual organization hierarchy management: Organizations -> Projects -> Environments -> Secrets. - Offers instant secret masking/unmasking, version history inspection, rollback mechanisms, and audit log exploration. - Supports team invitations, role assignments (Admin, Developer, Viewer), and API token generation. ## 3.2 Backend API (`apps/api`) - Built with Hono on Cloudflare Workers / Node.js. - Implements authenticated REST endpoints with JWT validation and API token bearer authentication. - Performs server-side AES-256-GCM envelope encryption for all secret values before persistence in Cloudflare D1 / PostgreSQL. - Maintains append-only audit log entries for all mutating operations. ## 3.3 Developer CLI (`apps/cli` / `@nex-x/cli`) - Terminal utility written in TypeScript. - Authenticates via browser OAuth or API token. - Commands: - `nexenv login`: Authenticates developer workstation. - `nexenv link`: Links local directory with a remote project. - `nexenv pull [--env ] [-o ]`: Fetches encrypted secrets and writes `.env.local`. - `nexenv run [--env ] -- `: Injects decrypted secrets directly into process memory without touching disk. - `nexenv push [--env ]`: Uploads local configuration to the vault. - `nexenv diff [--env ]`: Shows diff between local file and vault state. - `nexenv whoami`: Displays active user, organization, and API host. ## 3.4 Browser Extension (`apps/extension`) - Chrome Manifest V3 extension. - Authenticates with Nex-X Vault and detects active Cloudflare Pages / Workers or Vercel dashboard tabs. - Multi-strategy DOM injection: - Strategy 0: Direct Formik `envs[i].key` / `envs[i].value` attribute pairing. - Strategy 1: Smallest enclosing container discovery around `=` separators. - Strategy 2: Input placeholder and attribute traversal. - Emulates authentic user keystrokes via `document.execCommand('insertText')` and React `_valueTracker` synchronization to trigger native form state updates. # 4. Security Model & Compliance ## 4.1 Cryptographic Standards - **Algorithm**: AES-256-GCM (Galois/Counter Mode) authenticated encryption. - **Key Derivation**: PBKDF2 / Argon2 for master key expansion. - **Initialization Vectors**: Unique 96-bit cryptographically secure IV generated per variable encryption. - **Integrity Verification**: 128-bit authentication tag ensures ciphertext tampering is immediately rejected. ## 4.2 Access Control & Permissions - **Admin**: Full control over Organization, Projects, Billing, Team Roles, Audit Logs, and Production Secrets. - **Developer**: Read & Write access to Development and Staging environments; Read-Only or Restricted access to Production. - **Viewer**: Read-Only access to public/config variables; Secrets remain masked unless explicitly authorized. ## 4.3 Auditability Every read, pull, create, update, or delete action records: - Timestamp (UTC) - Actor ID & Email - Project ID & Environment - Action Type (e.g., `SECRET_READ`, `SECRET_UPDATE`, `CLI_PULL`, `EXTENSION_INJECT`) - IP Address & User Agent - Client Platform (`web`, `cli`, `extension`, `api`) # 5. Full Comparison Matrix | Feature | Nex-X ENV Vault | Plain .env Files | HashiCorp Vault | Doppler (SaaS) | AWS Secrets Manager | | :--- | :--- | :--- | :--- | :--- | :--- | | **Self-Hostable** | ✅ 100% Open Source | ❌ Manual | ✅ Complex | ❌ Closed Source SaaS | ❌ AWS Locked | | **Setup Time** | ⚡ < 60 Seconds | Instant (Unsafe) | ⏳ Weeks of Infra | ⏱️ 5 Minutes | ⏱️ 15 Minutes | | **Browser Extension** | ✅ 1-Click Cloudflare/Vercel | ❌ None | ❌ None | ⚠️ Limited | ❌ None | | **Developer CLI** | ✅ Fast (`nexenv pull/run`) | ❌ None | ⚠️ Heavyweight | ✅ Proprietary | ⚠️ Verbose AWS CLI | | **Data Sovereignty** | ✅ Total (Own Keys) | ⚠️ Unencrypted | ✅ Total | ❌ 3rd Party Hosted | ❌ Cloud Provider Hosted | | **Pricing** | 🆓 Free & Open Source | 🆓 Free | 💰 Expensive Enterprise | 💰 Per-seat subscription | 💰 Per-secret monthly fee |