.env Security Scanner
Scan a .env file for exposed API keys, high-entropy secrets and insecure defaults, with key patterns for OpenAI, Anthropic, AWS, Stripe and GitHub.
.env Security Scanner
All scanning runs locally in your browser. No data is sent to any server. Values are masked in the report output.
14 issues found, Critical risk
Issues (14)
NODE_ENVHighDevelopment Environmentdeve***mentSet NODE_ENV=production. Development mode disables optimizations and may expose debug endpoints.
DEBUGHighDebug Mode Enabled****Set DEBUG=false in production. Debug mode can leak stack traces and internal state.
DATABASE_URLCriticalDatabase URL with Credentialspost********************yappDatabase URL contains embedded credentials. Use a secrets manager and rotate the password.
REDIS_URLCriticalRedis URL with Passwordredi********************6379Redis URL contains embedded password. Use a secrets manager.
OPENAI_API_KEYCriticalOpenAI Project Keysk-p********************7890Rotate this OpenAI project key. Use a vault or CI/CD secret.
STRIPE_SECRET_KEYCriticalStripe Live Secret Keysk_l********************mnopURGENT: Live Stripe key exposed. Rotate at dashboard.stripe.com/apikeys immediately.
STRIPE_PUBLISHABLE_KEYLowStripe Publishable Livepk_l********************mnopPublishable keys are designed for client-side use but should still be managed carefully.
AWS_ACCESS_KEY_IDCriticalAWS Access Key IDAKIA************MPLERotate in AWS IAM console immediately. Use IAM roles or instance profiles instead.
AWS_SECRET_ACCESS_KEYCriticalAWS Secret Access KeywJal********************EKEYRotate the associated AWS secret key. Prefer IAM roles over long-lived credentials.
GITHUB_TOKENHighHigh-Entropy Secret (5.14 bits)ghp_********************efghThis value has high entropy and appears to be a secret. Store in a vault or secrets manager, not in .env files committed to version control.
SENDGRID_API_KEYCriticalSendGrid API KeySG.a********************nopqRevoke at app.sendgrid.com/settings/api_keys. Create a new key with minimal permissions.
JWT_SECRETCriticalPlaceholder Secret******Replace with a cryptographically random secret. Use `openssl rand -hex 32` to generate one.
ADMIN_PASSWORDCriticalWeak Password********Use a strong, unique password (16+ chars). Never use default passwords in any environment.
API_KEYMediumPlaceholder API Keyyour*****hereReplace with an actual API key. Placeholder values suggest the app may not be properly configured.
Updated . Provided as is. Check the output before you rely on it in production.
How to use .env Security Scanner
- 1
Paste your .env contents
Copy your .env file contents and paste them into the scanner. The tool parses standard KEY=VALUE format with support for quotes and comments.
- 2
Review per-variable findings
Each variable is analyzed individually. Detected API keys show the provider name and severity. High-entropy values are flagged as potential secrets. Insecure defaults are highlighted.
- 3
Check the risk score
The overall risk score (0-100) summarizes your .env security posture. Critical findings like production API keys significantly increase the score.
- 4
Copy the report
Click Copy Report to get a markdown summary of all findings with recommendations — share with your team or add to your security review process.
Questions and answers
What is .env Security Scanner?
How does it detect API keys?
Does it send my secrets to a server?
What insecure defaults does it catch?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/env-security-scanner/
For automation planning, fetch the canonical contract at /api/tool/env-security-scanner.json.