.env Formatter & Validator

Format, sort, and validate .env files. Auto-detects secrets and generates a safe .env.example template. 100% browser-based, nothing uploaded.

How to use

  1. Paste your .env file — Drop the full contents into the input box.
  2. Pick formatting rules — Sort alphabetically, uppercase keys, quote values with spaces.
  3. Copy formatted output or .env.example — Commit .env.example to git; keep the real .env private.

Why Formatting Your .env Matters

A messy .env file silently breaks deployments — mixed quoting causes parsing errors in one library and not another, inconsistent casing trips up case-sensitive lookups, and unsorted keys make diffs unreadable. A consistent format is one of those small habits that prevents large 3am incidents.

The Secret Leak Problem

The single biggest .env mistake is committing it to git. Public GitHub repos are crawled by bots within minutes; a leaked AWS key can rack up thousands of dollars in compute before you notice. The fix is twofold: add .env to .gitignore, and commit a .env.example template so collaborators know which variables to provide.

How This Tool Helps

It does three things at once: validates KEY=VALUE syntax (flagging lines that won't parse in any dotenv library), formats the file consistently (sort, uppercase, quote-when-needed), and generates a safe .env.example by replacing any value with a key matching common secret patterns (KEY, TOKEN, SECRET, PASSWORD, etc.) with a placeholder.

What It Doesn't Do

It doesn't validate that your variables are actually used by your app, doesn't enforce a schema (use envalid or zod for that), and doesn't support multiline values or variable interpolation. The goal is a clean baseline; project-specific validation belongs in your runtime code.

If You've Already Leaked a Secret

Assume compromise. Rotate the credential immediately, then use BFG Repo-Cleaner or git filter-repo to scrub the secret from history, force-push, and ask collaborators to re-clone. Just deleting the file in a new commit isn't enough — git history preserves everything.

Frequently asked questions

Is my .env file uploaded anywhere?

No. Parsing, formatting, and secret detection all happen in your browser using plain JavaScript regexes. Nothing is sent to a server. You can verify by opening DevTools → Network tab while you paste.

What counts as a 'secret'?

Any key whose name matches KEY, TOKEN, SECRET, PASSWORD, PWD, API, PRIVATE, DSN, or AUTH (case-insensitive). The tool highlights these and replaces their values with placeholders in the generated .env.example. Treat the heuristic as a starting point, not a guarantee — review manually.

Why generate a .env.example?

Committing .env to git leaks production secrets. The standard practice is to commit .env.example (with empty or placeholder values) so teammates know which variables they need to define locally — without exposing real credentials.

What's the difference between quoted and unquoted values?

Most .env parsers treat values literally — VAR=hello world keeps the space. But values containing #, \ , or quotes need to be wrapped in double quotes for safe parsing across dotenv libraries. The 'quote when needed' option handles this automatically.

Does it support multiline values or variable interpolation?

Not yet. This formatter focuses on the common case: KEY=value pairs, one per line, with optional comments. For advanced syntax (multiline, ${' }{OTHER_VAR}), use a project-specific tool like dotenv-expand and validate at runtime.

Related free tools

  • XML Formatter & Minifier — Beautify or minify any XML — SOAP, RSS, SVG, sitemap. Browser-based parser.
  • XML to JSON Converter — Parse any well-formed XML into a clean JSON tree with attributes and arrays.
  • JSON to XML Converter — Convert JSON to well-formed XML — supports attributes, custom root, declaration.
  • CSV Viewer — Open CSV or TSV files in your browser — sort, search, paginate, export filtered view.
  • JSON to CSV Converter — Convert JSON data to CSV format. Export to spreadsheets easily.
  • CSV to JSON Converter — Convert CSV data to JSON format. Useful for API development.
  • JSON Formatter — Format, beautify, or minify JSON with customizable indentation.
  • JSON Validator — Validate JSON syntax and find errors with line and column numbers.
  • HTML Minifier — Compress HTML by removing comments, whitespace, and line breaks.
  • CSS Minifier — Minify CSS by stripping comments, whitespace, and unnecessary characters.
  • JavaScript Minifier — Compress JavaScript by removing comments, whitespace, and empty lines.
  • Base64 Encoder/Decoder — Encode text to Base64 or decode Base64 back to text. UTF-8 support.

Browse all free tools · Guides and tutorials · PDF tools · Developer tools · Text tools · SEO tools