ENV Validator

File A

Findings

0 issues

No problems detected — every line is well-formed with a unique key.

Values are only ever compared, never logged. Keep secrets in these files — they stay in your browser.

ENV Validator

Validate and compare .env files in your browser. Check syntax and duplicates, then diff your local secrets against your .env.example — all locally, nothing uploaded.

About this tool

What is it?
DataFormatter ENV Validator is a free online tool that checks .env syntax, duplicates and formatting, then diffs a local file against its .env.example.
Who is it for?
Developers and DevOps engineers who want to confirm configuration files are well-formed and complete before deploying.
What makes DataFormatter's tool different?
Analysis happens entirely in the browser, so secret values never leave your machine.

Quick start

  1. Paste your .env contents into File A (validation runs instantly).
  2. Review line-by-line findings, or switch to Compare A vs B and paste your .env.example into File B.
  3. Use the three diff lists: missing keys, extra keys, and changed values.
  4. Copy or download the report for your team or a ticket.

What ENV validation catches

  • Duplicate keys — most loaders keep only the last value; your config is silently wrong.
  • Empty values like API_KEY= that often mean a missing secret, not an intentional blank.
  • Spaces around the equals (KEY = value) — tolerated by some parsers, rejected by others.
  • Invalid names — leading digits, hyphens and other characters that engines refuse or mangle.
  • Stray leading/trailing whitespace that shifts the key or the value unexpectedly.
  • Lines that are neither a KEY=VALUE pair, a comment, nor blank.

Who validates .env files — and when

Before you push .env.example

Run the diff against your local file to guarantee the example lists every key you actually use — and nothing stale.

Mysterious config drift

Production behaves differently from your laptop. Diff your local .env against the deployed file (via a safe channel) and find the changed key.

Onboarding a new team member

Send them the validator findings window as the checklist: add these keys, remove these, fix these values.

When the report looks odd

"Duplicate key" you didn't expect

Why: The same key appears twice — maybe once in an export NODE_ENV=… line and once plain, or across two pasted stanzas.

Fix: Search the file for the key name and merge the duplicates; keep the last occurrence's value.

Spaces-around-equals on a health check line

Why: Some generators emit KEY = value with spaces, which this validator flags as fragile.

Fix: Normalize to KEY=value — jjdotenv and most runtimes accept only the tight form.

A line you expect to be valid is flagged unquoted

Why: Values containing # comments or spaces benefit from quotes; without them parsing is ambiguous.

Fix: Wrap the value in double quotes and escape inner quotes/backslashes as your runtime expects.

Pro tips

  • Always keep the example file in sync — the diff is only as honest as the source of truth.
  • Diff before a deploy to catch a key you added in code but never put in CI environments.
  • Pair with the Fake Data generator for non-secret placeholders you need to fill mock config.
  • The validator runs locally, so real tokens and connection strings are safe to paste.

Frequently asked questions

What does the validator check?

Every line of your .env file: invalid key names, empty values, duplicate keys, stray spaces before/after the key, spaces around the equals sign, and lines that aren't a comment, blank line or KEY=VALUE pair. Values are never logged or sent anywhere.

Why would I use Compare A vs B?

To check your local .env against your .env.example (or a teammate's). You get three lists: keys in the example that are missing from your file, keys that exist only in yours, and keys whose values differ.

Are secrets shown in the output?

The diff lists key names and (truncated) values, and the report you copy/download names keys but never values unless a value differs from the example. Real secret values are never transmitted anywhere.

What counts as an invalid name?

dotenv-compatible names: start with a letter or underscore, then letters, digits and underscores. Lines like 123=value or MY-KEY=value are flagged invalid.

Does it catch duplicate keys?

Yes — and this is the dangerous one, because most loaders silently keep the last occurrence. The validator flags every definition of a key that appears more than once.

Can it read export-prefixed lines?

Yes. Lines like export NODE_ENV=production are parsed too (the export keyword is stripped), matching what dotenv with export support and shell sourcing do.

Related tools

Last reviewed September 2026 · DataFormatter team — this tool processes data locally in your browser.