Overview
Compares two .env files key by key and lists every variable that was added, removed or changed between them. Secret values are masked by default, so you can check a staging file against production, or .env.example against a real .env, without exposing passwords on screen or in the report you download.
How It Works
Paste one file on each side and, if you like, give them names such as .env.staging and .env.production. The counters show how many keys were added, removed, changed or unchanged, and the list below names each key. Tick Show secret values to reveal real values, and List unchanged keys to include identical entries. Swap sides flips the comparison direction. The plain-text report updates as you type and can be copied or downloaded.
Step-by-Step Usage Guide
- Paste the first .env file into the left box and the second into the right box.
- Read the added, removed and changed counters, then scan the list for keys that exist on one side only.
- Leave Show secret values off unless you need to confirm a specific value.
- Copy or download the report to attach to a pull request, ticket or deployment checklist.
Technical Specifications & Standards
Each side is parsed the way common dotenv loaders read a file. Blank lines and lines starting with # are skipped, and an export prefix is accepted. Unquoted values end at a # that follows whitespace, so a URL fragment such as http://host/#top keeps its hash. Double-quoted values understand the escapes \n, \r, \t, \" and \\, single-quoted and backtick values are taken literally, and a quoted value can run over several lines. If a key appears twice, the last definition wins, as it does when the file is loaded, and the tool lists the duplicate so you notice it. Comparison is on the resulting text: A=1 and A="1" are equal, key order does not matter, and an empty value is different from a missing key. Variable references such as ${HOME} are not expanded, so they are compared as written. Masking is heuristic. A value is hidden when its key contains words like SECRET, TOKEN, PASSWORD, KEY, AUTH or DSN, when it looks like a known token format (JWT, GitHub, Stripe, Slack or AWS access key IDs) or a long random string, and the password part of a URL such as postgres://user:password@host is hidden while the host stays visible. A secret with an unremarkable name and a plain-looking value would not be caught, so read the report before sharing it.
Targeted Use Cases
- Checking that production defines every variable staging does before a release.
- Finding keys missing from .env.example after a teammate adds a new setting.
- Reviewing which values differ between two developers' local environment files.
- Auditing a migration from one host to another by comparing exported environments.
Notes & Gotchas
- Keep the masking on when sharing screenshots or reports, and never paste production secrets into a chat.
- Treat a key that is missing on one side as the first thing to fix, since it usually causes a runtime failure rather than a wrong value.
- Watch the duplicate-key notice, because the earlier definition is silently ignored.
- Commit a current .env.example and compare it with real files whenever you add a variable.
Frequently Asked Questions
Are my secrets uploaded anywhere?
No. Both files are parsed and compared in your browser, and nothing is sent to a server. Values are masked on screen and in the report unless you choose to reveal them.
Does it detect every secret?
No. It masks by key name, known token formats, long random-looking strings and passwords inside URLs. A secret with a harmless name and a short, ordinary-looking value can slip through, so check before sharing.
Will different quoting make a key show as changed?
No. Quotes are removed before comparing, so A=1 and A="1" are equal. A key is changed only when the resulting value text differs, including differences in spaces inside quotes.
Does it expand variables such as ${PORT} or run shell commands?
No. References are compared as literal text and nothing is evaluated, so the result does not depend on your machine's environment.