Skip to content

.env Security Scanner

Scan a .env file for exposed API keys, high-entropy secrets and insecure defaults, with key patterns for OpenAI, Anthropic, AWS, Stripe and GitHub.

.env Security Scanner

47 key patterns loaded
18 variables detected

All scanning runs locally in your browser. No data is sent to any server. Values are masked in the report output.

14 issues found, Critical risk

18
Total variables
14
Issues found
100
Risk score
Critical risk
Assessment
Risk level100/100

Issues (14)

NODE_ENVHighDevelopment Environment
deve***ment

Set NODE_ENV=production. Development mode disables optimizations and may expose debug endpoints.

DEBUGHighDebug Mode Enabled
****

Set DEBUG=false in production. Debug mode can leak stack traces and internal state.

DATABASE_URLCriticalDatabase URL with Credentials
post********************yapp

Database URL contains embedded credentials. Use a secrets manager and rotate the password.

REDIS_URLCriticalRedis URL with Password
redi********************6379

Redis URL contains embedded password. Use a secrets manager.

OPENAI_API_KEYCriticalOpenAI Project Key
sk-p********************7890

Rotate this OpenAI project key. Use a vault or CI/CD secret.

STRIPE_SECRET_KEYCriticalStripe Live Secret Key
sk_l********************mnop

URGENT: Live Stripe key exposed. Rotate at dashboard.stripe.com/apikeys immediately.

STRIPE_PUBLISHABLE_KEYLowStripe Publishable Live
pk_l********************mnop

Publishable keys are designed for client-side use but should still be managed carefully.

AWS_ACCESS_KEY_IDCriticalAWS Access Key ID
AKIA************MPLE

Rotate in AWS IAM console immediately. Use IAM roles or instance profiles instead.

AWS_SECRET_ACCESS_KEYCriticalAWS Secret Access Key
wJal********************EKEY

Rotate the associated AWS secret key. Prefer IAM roles over long-lived credentials.

GITHUB_TOKENHighHigh-Entropy Secret (5.14 bits)
ghp_********************efgh

This value has high entropy and appears to be a secret. Store in a vault or secrets manager, not in .env files committed to version control.

SENDGRID_API_KEYCriticalSendGrid API Key
SG.a********************nopq

Revoke at app.sendgrid.com/settings/api_keys. Create a new key with minimal permissions.

JWT_SECRETCriticalPlaceholder Secret
******

Replace with a cryptographically random secret. Use `openssl rand -hex 32` to generate one.

ADMIN_PASSWORDCriticalWeak Password
********

Use a strong, unique password (16+ chars). Never use default passwords in any environment.

API_KEYMediumPlaceholder API Key
your*****here

Replace with an actual API key. Placeholder values suggest the app may not be properly configured.

Updated . Provided as is. Check the output before you rely on it in production.

How to use .env Security Scanner

  1. 1

    Paste your .env contents

    Copy your .env file contents and paste them into the scanner. The tool parses standard KEY=VALUE format with support for quotes and comments.

  2. 2

    Review per-variable findings

    Each variable is analyzed individually. Detected API keys show the provider name and severity. High-entropy values are flagged as potential secrets. Insecure defaults are highlighted.

  3. 3

    Check the risk score

    The overall risk score (0-100) summarizes your .env security posture. Critical findings like production API keys significantly increase the score.

  4. 4

    Copy the report

    Click Copy Report to get a markdown summary of all findings with recommendations — share with your team or add to your security review process.

Questions and answers

What is .env Security Scanner?
A .env file holds an app's environment variables, often API keys, passwords and database URLs, so it often leaks credentials. This scanner matches values against the key formats of common providers, flags high-entropy strings and catches insecure defaults like DEBUG=true, placeholder secrets and disabled SSL checks.
How does it detect API keys?
The tool uses provider-specific regex patterns (e.g., OpenAI keys start with sk-, AWS access keys start with AKIA) and Shannon entropy analysis for detecting high-entropy values that are likely secrets.
Does it send my secrets to a server?
Absolutely not. All scanning happens entirely in your browser. Your .env contents — which contain your most sensitive credentials — never leave your device.
What insecure defaults does it catch?
Common defaults like DEBUG=true, PASSWORD=password, SECRET=changeme, API_KEY=your_key_here, and empty values for security-critical variables. Each finding includes a recommendation for the correct approach.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/env-security-scanner/

For automation planning, fetch the canonical contract at /api/tool/env-security-scanner.json.