🌱Env File Syntax Checker

Check .env syntax line by line

This tool masks values and never sends your input out of the browser. Even so, do not paste real keys and values while sharing or recording your screen. A secret that has been exposed should be rotated.

You Might Also Need

About This Tool

Paste your .env content and each line is checked, with problems reported by line number. The checks cover a missing equals sign, characters that cannot appear in a key, unbalanced quotes, whitespace around the equals sign and at the end of a value, duplicate keys, the boundary between a value and a comment, CRLF line endings and a byte order mark. Findings are split into errors, warnings and notes.

Values are never printed; only their length survives, behind a mask. A .env file holds database passwords and API keys, and a screen left open for checking is itself a leak once it is captured or shared. Input is processed inside the browser and never sent to a server, but a secret that has already been exposed should be rotated rather than reused. Checked against widely used dotenv conventions as of October 2026.

There is no single official .env specification. dotenv libraries, shells and Docker Compose each treat quotes, whitespace, the hash sign and variable expansion differently, so anything parsers disagree about is reported as a warning rather than an error; confirm the real behavior in the docs for your parser. Whether a value is correct, or whether the address it points at is reachable, is not checked.

Frequently Asked Questions

Why are the values hidden?

A .env file normally holds passwords and tokens. Printing them in a results panel exposes them to screenshots, screen sharing and anyone looking over your shoulder, so only the character count is kept. Checking syntax does not require the content of a value.

Why is a space in an unquoted value a warning?

Some parsers read the whole line including the space, others stop at it, and sourcing the file in a shell can make it a syntax error outright. Values containing a space or a hash are safer wrapped in quotes.

What does this tool not do?

It does not check whether a value is correct, whether a connection string is reachable, or whether a secret is still valid. It only looks at syntax and structure.