All tools

Laravel .env checker

Find missing keys, duplicates, spaces in unquoted values, an empty APP_KEY, APP_DEBUG in production and secrets in .env.example. Runs entirely in your browser; your values are never uploaded or shown.

Private by design. This runs entirely in your browser. Nothing you paste is uploaded, stored or logged, and results show key names and line numbers, never values.

Paste both to compare them, or just one to check its syntax. Up to 256,000 characters per file.

Results appear here as you paste.

Why this exists

Most Laravel outages caused by configuration are boring: a variable added to .env.example but never set in production, a value with a space that makes the dotenv parser throw, an APP_KEY left empty, or APP_DEBUG=true on a live server. They are easy to find by eye in a five-line file and easy to miss in a hundred-line one.

Paste your .env and your .env.example and this checker compares them. It follows the same parsing rules as the dotenv library Laravel uses, so it flags what actually breaks a boot. Because .env files are full of secrets, it is built so that values are never displayed, logged or sent anywhere: findings only name keys and line numbers.

How it works

  • Both files are parsed with phpdotenv-style rules: optional export, single and double quotes (including multi-line values), # comments, and the rule that an unquoted value containing spaces is an error.
  • The two key sets are compared to find keys missing from .env, keys undocumented in .env.example, and defaults that were blanked out.
  • Built-in checks cover APP_KEY presence and format, APP_DEBUG with APP_ENV=production, duplicate keys, ${VAR} references to variables not defined earlier, a UTF-8 byte-order mark that corrupts the first key, and values in .env.example that look like real credentials.
  • The "missing keys" block gives you `KEY=` lines ready to paste; it only copies an example default when it is clearly not sensitive.

Examples

Spaces in an unquoted value
APP_NAME=My Great App → error: wrap it in double quotes, APP_NAME="My Great App"
Debug left on in production
APP_ENV=production with APP_DEBUG=true → error: stack traces and environment details would be exposed.
A key added to .env.example only
REDIS_HOST is documented but missing from .env → reported, with a ready-made REDIS_HOST= line.

Limitations

  • It cannot see variables that your server, container or CI injects at runtime, so a key missing from .env may still be provided elsewhere.
  • Secret detection is heuristic: it can miss an unusual credential and may flag a harmless long random value. It never proves a file is safe.
  • It checks syntax and consistency, not whether values are correct (a wrong database host still parses).
  • Very large inputs are refused (256,000 characters or 5,000 lines per file) to keep the page responsive.
  • Which duplicate definition wins depends on how the file is loaded, so the checker reports duplicates rather than choosing one.

Privacy

Your files never leave this page: there is no upload, no request containing your text, no analytics on what you paste, and nothing is stored in cookies or local storage. Findings show key names and line numbers, never values. Closing or reloading the tab discards everything.

Site-wide, this website uses cookie-free analytics that count page views and button clicks only. See the privacy notes.

Frequently asked questions

Is it safe to paste my production .env?

The page processes text locally and sends nothing, which you can confirm in your browser's network panel. Even so, treat production secrets carefully: prefer checking a copy with real secrets replaced, and rotate anything you have ever pasted somewhere you did not control.

Why does APP_NAME=My App break Laravel?

The dotenv parser rejects an unquoted value containing whitespace with an "unexpected whitespace" error at boot. Quote the value: APP_NAME="My App".

What does php artisan key:generate do?

It writes a random base64 APP_KEY into .env. Laravel uses it to encrypt cookies and sessions, so an empty or changing key logs everyone out and can break encrypted data.

Should .env be committed to git?

No. Commit .env.example with safe placeholders and keep .env out of version control. This checker warns when .env.example appears to contain a real credential.