.env Diff
Compare and validate .env files
Compare two .env files to find missing, extra and changed keys, catch duplicates and syntax problems, with values masked.
- dotenv
- .env
- Config
How to use .env Diff
- Paste the reference file (for example
.env.example) into File A and the file to check (for example.env) into File B. You can also use Open file A / Open file B, drop a file on either box, or press Try an example. - Read the problems listed under each file: syntax errors, unclosed quotes, unquoted values with
#or spaces, and keys set more than once. - In the differences table, use Show to filter to Missing (in A but not B), Extra (only in B), Changed or Same keys. Values are masked; press Reveal on a row to see them and Hide all to mask them again.
- Check the Looks secret badges, which flag values that appear to be passwords, tokens or keys.
- Under Generate .env.example from, pick File A or File B to get the same file with every value removed, then copy or download it.
How it works
Each file is parsed with dotenv’s rules. Blank lines and lines starting with # are skipped, an optional export prefix is accepted, and each line is KEY=value (or KEY: value). Keys start with a letter or _ and may contain letters, digits, _, . and -. Double-, single- and backtick-quoted values may span several lines. In double quotes \n, \r, \t, \", \\ and \$ are unescaped; single-quoted values are taken literally. In an unquoted value everything from # on is a comment and surrounding spaces are trimmed. When a key appears more than once, the last value wins, as in dotenv.
The comparison uses each file’s final parsed values, so A="x" and A=x count as the same. ${VAR} and $VAR references are listed, not expanded. A key is flagged as secret-looking when its name contains words such as SECRET, TOKEN, PASSWORD, API_KEY or PRIVATE, when its value matches a known token format (Stripe, GitHub, Slack, AWS, Google, GitLab, npm, JWTs, PEM private keys), when it is a URL with a password, or when it is a long, random-looking string.
Limits
- Variable references are never expanded, and there is no support for dotenv-expand defaults or command substitution.
- Lines that aren’t valid assignments (no
=, invalid key names, quotes that are never closed) are reported and left out of the comparison and the generated.env.example. - Secret detection is a heuristic based on names, known token prefixes and randomness. It can miss secrets and flag harmless values.
- Masked values show between 4 and 12 dots, so a masked value still gives a rough idea of its length.
- Opened or dropped files must be text and at most 10 MB.
Privacy
Both files are parsed and compared entirely in your browser; nothing is uploaded or saved, and the site’s Content Security Policy blocks requests to other servers. Values stay masked on screen until you reveal them. This tool has no share links, so your files never end up in a URL. Only the generated .env.example, which contains keys and comments but no values, can be copied, downloaded or passed on with Send to…, which hands it over through this tab’s session storage and removes it as soon as the other tool reads it.
Frequently asked questions
Is it safe to paste a real .env file here?
The files are processed only in your browser and never sent anywhere or stored, and values stay masked unless you reveal them. As with any secret, avoid revealing values while sharing your screen.
Which file should be A and which B?
Put the reference in File A, usually .env.example, and the file you are checking in File B. Missing then means a key your app expects but B doesn’t set, and Extra means a key only B has.
Why is part of my value missing?
In an unquoted value, dotenv treats everything from # on as a comment. The tool warns when a # touches the value, as in abc#123. Wrap the value in quotes to keep the #.
What happens when a key is defined twice?
The last assignment wins, as in dotenv. The tool lists every duplicate with its line numbers, and the comparison uses the final value.
Are ${VAR} references resolved?
No. They are listed under the value as references, but the text is compared as written. Two files that reference the same variable compare as the same even if it would expand differently.
How is the .env.example generated?
Every valid assignment becomes KEY= with its value removed, keeping export, comments and blank lines. Multiline values collapse to a single KEY= line, a key set twice appears twice, and lines that couldn’t be parsed are dropped.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- Kubernetes YAML Checker: Validate and explain Kubernetes manifests
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones