---
title: "Keep a file private in a shared repo"
url: https://loot.build/docs/guides/private-env
group: "Guides"
status: written
summary: "Declare it restricted; non-keyholders carry ciphertext."
---

# Keep a file private in a shared repo

> Declare it restricted; non-keyholders carry ciphertext.

Declare the path restricted before you record it. Only listed identities get a key; everyone else carries ciphertext.

```bash
printf '.env restricted=alice\n' > .lootattributes
loot describe -m "add sealed .env"
loot push          # the relay stores it but cannot read it
```
