dotenvcheck cross-checks the environment variables used in your Python code against those declared in your .env and docker-compose.yml files.
It reports unused, missing, and mismatched variables — helping you keep your environment configuration clean and consistent.
For example, if you’ve ever had a project with 20 variables in .env but only 10 actually used, dotenvcheck instantly shows you which ones can be safely removed or fixed.
Installation
pip install dotenvcheck
# or
pipx install dotenvcheck
# with docker-compose support
pip install "dotenvcheck[compose]"
Usage
From your project root (where .env lives):
dotenvcheck .
You’ll get a report listing missing, unused, or suspicious environment variables.
Example output:
== dotenvcheck report ==
unused (2): DATABASE_URL, NOTUSEDAPI_KEY
sources:
API_KEY: .env
DATABASE_URL: .env
DEBUG: .env
NOTUSEDAPI_KEY: .env
Configuration (optional)
You can configure defaults globally for your project via a [tool.dotenvcheck] section in your pyproject.toml.
[tool.dotenvcheck]
exclude = [".venv", "venv", "env", ".git", "__pycache__", "dist", "build", "node_modules"]
fail_on = ["missing"]
dotenv = ".env"
include = "*.py"
Options
| Key | Type | Default | Description |
|---|---|---|---|
exclude |
list of strings | [".venv", "venv", "env", ".git", "__pycache__", "dist", "build", "node_modules"] |
Directories or file patterns to ignore while scanning your code. |
include |
string or list of strings | "*.py" |
Glob pattern(s) of files to include when scanning for environment variable usage. |
dotenv |
string | ".env" |
Path to your .env file used for validation. |
fail_on |
list of strings | ["missing"] |
Determines which findings trigger a non-zero exit code. Options: "missing", "typos", "bad_values", "unused". |
Behavior
- Ignores common directories like
.venv,dist/,build/, and.git/by default. - Command-line arguments always override
pyproject.toml. - Works seamlessly across macOS, Linux, and Windows.
- Fully supports Python 3.8 → 3.12+.
Project structure
dotenvcheck/
├─ src/
│ └─ envguard/
│ ├─ __init__.py
│ ├─ __main__.py
│ ├─ cli.py
│ ├─ scanner.py
│ ├─ dotenv.py
│ ├─ compose.py
│ └─ report.py
├─ tests/
├─ pyproject.toml
├─ LICENSE
├─ README.md
└─ .github/
└─ workflows/
├─ test.yml
└─ workflow.yml
License
MIT License – feel free to use, modify, and contribute.
Release files for dotenvcheck 0.1.9
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dotenvcheck-0.1.9.tar.gz | 7.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dotenvcheck-0.1.9-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 17.3 kB
Release files / dotenvcheck-0.1.9.tar.gz
| Download URL | dotenvcheck-0.1.9.tar.gz |
|---|---|
| Size | 7.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
36bd6474b9cbe9248d9d45d2cd9074d9690ca0e251682533ba478e0ea02c9a30
|
|
BLAKE2b-256 checksum How to use checksums |
21627265a7e561f837cadbc17dc98424222558930698d50dc9f27ad913c79bb1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 23, 2025.
Transparency logRelease files / dotenvcheck-0.1.9-py3-none-any.whl
| Download URL | dotenvcheck-0.1.9-py3-none-any.whl |
|---|---|
| Size | 9.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
58af6b1c90e387ce88d2cabdce6ac20a4bbc0f761fd8ecc90cad39154774b712
|
|
BLAKE2b-256 checksum How to use checksums |
85f1a9018a6393cb1a029f5d67180ff2582f717392ae1b6e7b8ba733ee7b7710
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 23, 2025.
Transparency log