Varlock now includes "credential brokering" functionality - your agent (or whatever process) gets only _placeholder_ credentials, and real secrets are swapped in over the wire (MITM proxy). Rules are configured in your existing .env.schema Would love to hear your feedback!
varlock.dev
@varlock.dev
Building the future of configuration for humans and non-humans varlock.dev
I was previously tending a booth for a product called Varlock. They're incredibly useful for credentials management. Definitely worth a look. They brand themselves as "credentials management in the AI era". https://github.com/dmno-dev/varlock
GitHub - dmno-dev/varlock: AI-safe .env files: Schemas for agents, Secrets for humans.
AI-safe .env files: Schemas for agents, Secrets for humans. - dmno-dev/varlock
github.com
Super fun chatting with @brandonwhichard.com about varlock. He is a real user - found us through a listener and has been using it ever since. Have a listen! 🎧
Every project has environment variables. Almost nobody manages them well. This week @brandonwhichard.com talks with Phil Miller and @theozero.bsky.social, who built varlock to fix that — bringing structure and security to the humble .env file. https://www.softwaredefinedtalk.com/580
The .env file: every project has one, almost nobody manages it well. This week I sat down with the founders of varlock to talk about fixing that.
Every project has environment variables. Almost nobody manages them well. This week @brandonwhichard.com talks with Phil Miller and @theozero.bsky.social, who built varlock to fix that — bringing structure and security to the humble .env file. https://www.softwaredefinedtalk.com/580
"Everyone has a place for Varlock in their tech stack." Thanks for the great conversation @softwaredefinedtalk.com www.softwaredefinedtalk.com/580
Varlock: Bringing Order to the Chaos of Environment Variables
Every project has environment variables. Almost nobody manages them well. This week Brandon talks with Phil Miller and Theo Ephraim, who built varlock to fix that — bringing structure and security to ...
softwaredefinedtalk.com
🧙♂️ varlock@1.10 adds arbitrary codegen. As well as built-in support for php, python, go, rust - so you get a fully typed+coerced env loader to use in your code. Plugins can add codegen types - new possibilities to generate for k8s, terraform... anything! varlock.dev/guides/code-...
Code generation
Generate types and other code from your env schema, and extend it with plugins
varlock.dev
Say hello to 🐣 fledgling - a new tool to create new npm packages and setup/sync trusted publishing (OIDC) settings. Works great for one offs, but even better in a monorepo! just `npx fledgling`
New varlock+mise guide varlock.dev/integrations... Would appreciate a look from any heavy mise users!
mise
Install varlock with mise and wire validated env vars into your tasks
varlock.dev
⚡️ We're looking for a DevRel person at @vlt.sh - based in our Toronto 🇨🇦 HQ. You'll work closely w/ me & should love the idea of owning various aspects of product marketing. You'll be vlt's biggest fan & advocate; molding this unique role in a way that plays to your strengths & ours.
Toronto friends! we're looking for a DevRel to join the @vlt.sh team there! #hiring #toronto www.vlt.io/careers/deve...
Developer Relations Engineer | Careers | vlt /vōlt/
As a Developer Relations Engineer, you will serve as the bridge between vlt and the global JavaScript community. This role combines technical expertise, community engagement, and developer-focused mar...
vlt.io
This is an awesome writeup! Another helpful precaution I've been yelling about: get EVERY secret out of plaintext. Many malicious scripts are harvesting creds from .env and other config files. varlock.dev can help
Varlock - AI-safe .env files
AI-safe .env files: schemas for agents, secrets for humans. Validate, secure, and share environment variables with type-safety, leak prevention, and integrations for Next.js, Vite, Astro, and more.
varlock.dev
Thanks for the shout out @softwaredefinedtalk.com www.softwaredefinedtalk.com/571 (~47:00)
The Enterprise Dunbar number
This week, we discuss AI labs driving cloud revenue, hyperscalers laying off instead of building, and kids defeating age verification. Plus, Brandon has too many thoughts on Workday.
softwaredefinedtalk.com
As of today @varlock.dev has OIDC workload identity support - this means that for some popular combos of deployment platform + secret storage, you no longer need a secret-zero to pull the rest of your sensitive data. check out varlock.dev/guides/oidc/ to get started
OIDC Workload Identity
Authenticate with secret providers using OIDC tokens from your deployment platform — no long-lived credentials needed
varlock.dev
Introducing bumpy 🐸 - a new version/release/changelog tool (carefully crafted slop fork of changesets 🦋) Fixes 100s of open issues, much simpler, more flexible. We use it to release @varlock.dev and 25+ linked plugins/libs. bumpy.varlock.dev
DMNO (varlock) was one of the fastest growing open-source orgs on GitHub in Q1. Thanks for the recognition @supabase.com >commitvc #osscarindex osscar.dev/org/dmno-dev
DMNO — OSSCAR Q1 2026
DMNO on OSSCAR Q1 2026 with a composite score of 3.000.
osscar.dev
To celebrate @cloudflare.social's epic week - the new @varlock.dev workers integration got a revamp and it is RAD. We totally fixed env vars in workers. varlock.dev/integrations... Full validation, pull from anywhere, set env atomically w/ each deploy. No more mix of .dev.vars/.env/wrangler.toml
Cloudflare Workers
How to integrate varlock with Cloudflare Workers and Wrangler for secure, type-safe environment management
varlock.dev
Unlock the potential of your AI projects with dmno-dev/varlock. Secure your .env files with schemas designed for agents and secrets meant for humans. https://sinapti.ca/post/en/varlock-typed-schema-environment-variables-to-protect-secret-w6tei9mw
Varlock: typed schema environment variables to protect secrets in AI projects, over 3,000 stars on GitHub - Sinaptica
If you use AI agents for programming, you already know the risk: the assistant reads your work environment and, with it, your secrets. Varlock elegantly solves
sinapti.ca
March recap — featuring @nextjs.org (full Turbopack), @cloudflare.social Workers, @expo.dev & plugins for @dashlane.com @hashicorp.com @proton.me me @passbolt.bsky.social (+ KeePass & unix pass): varlock.dev/blog/march-2...
March 2026 Recap
varlock@0.7.0 adds better plugin authoring with ESM/TypeScript single-file plugins, the Next.js integration gains full Turbopack support, we launch Cloudflare and Expo integrations, and the community ...
varlock.dev
Stoked to be featured in @nickyt.online 's awesome One Tip a Week newsletter which is quickly becoming one of our favourites. one-tip-a-week.beehiiv.com/p/one-tip-a-...
One Tip a Week: Stop Shipping Broken Env Config
one-tip-a-week.beehiiv.com
🚀 Skyrocketing! 🚀 (200+ new stars) 📦 dmno-dev / varlock ⭐ 2,270 (+357) 🗒 TypeScript .env files built for sharing powered by @env-spec decorator comments
GitHub - dmno-dev/varlock: .env files built for sharing powered by @env-spec decorator comments
.env files built for sharing powered by @env-spec decorator comments - dmno-dev/varlock
github.com
We appreciate the post and the feedback @jesse.id ! Those getting started docs are due for an update :) jesse.id/blog/posts/u...
Listened to the pod, but visiting varlock.dev made it so much better... The artwork is awesome! Will try varlock tomorrow! Also starred the repo 🌟
varlock
varlock.dev
varlock was featured on our favourite webdev podcast @syntax.fm today :) Check it out! www.youtube.com/watch?v=M5Ik...
Stop putting secrets in .env
YouTube video by Syntax
youtube.com
Who knows how to secure open source better than the maintainers themselves? 🛡️
Varlock was one of the projects selected for the @github.com Secure Open Source Fund! We worked with security experts to level up our fundamentals like threat modeling, responsible disclosure, automated scanning, and more. Here's what we learned and shipped: varlock.dev/blog/github-...
How Varlock Is Leveling Up Security Through the GitHub Secure Open Source Fund
varlock.dev