Skip to main content

dotenvcheck cross-checks the environment variables used in your Python code against those declared in your .env and docker-compose.yml files. It reports unused, missing, and mismatched variables — helping you keep your environment configuration clean and consistent.

For example, if you’ve ever had a project with 20 variables in .env but only 10 actually used, dotenvcheck instantly shows you which ones can be safely removed or fixed.


Installation

pip install dotenvcheck
# or
pipx install dotenvcheck

# with docker-compose support
pip install "dotenvcheck[compose]"

Usage

From your project root (where .env lives):

dotenvcheck .

You’ll get a report listing missing, unused, or suspicious environment variables.

Example output:

== dotenvcheck report ==
unused (2): DATABASE_URL, NOTUSEDAPI_KEY

sources:
  API_KEY: .env
  DATABASE_URL: .env
  DEBUG: .env
  NOTUSEDAPI_KEY: .env

Configuration (optional)

You can configure defaults globally for your project via a [tool.dotenvcheck] section in your pyproject.toml.

[tool.dotenvcheck]
exclude = [".venv", "venv", "env", ".git", "__pycache__", "dist", "build", "node_modules"]
fail_on = ["missing"]
dotenv = ".env"
include = "*.py"

Options

Key Type Default Description
exclude list of strings [".venv", "venv", "env", ".git", "__pycache__", "dist", "build", "node_modules"] Directories or file patterns to ignore while scanning your code.
include string or list of strings "*.py" Glob pattern(s) of files to include when scanning for environment variable usage.
dotenv string ".env" Path to your .env file used for validation.
fail_on list of strings ["missing"] Determines which findings trigger a non-zero exit code. Options: "missing", "typos", "bad_values", "unused".

Behavior

  • Ignores common directories like .venv, dist/, build/, and .git/ by default.
  • Command-line arguments always override pyproject.toml.
  • Works seamlessly across macOS, Linux, and Windows.
  • Fully supports Python 3.8 → 3.12+.

Project structure

dotenvcheck/
├─ src/
│  └─ envguard/
│     ├─ __init__.py
│     ├─ __main__.py
│     ├─ cli.py
│     ├─ scanner.py
│     ├─ dotenv.py
│     ├─ compose.py
│     └─ report.py
├─ tests/
├─ pyproject.toml
├─ LICENSE
├─ README.md
└─ .github/
   └─ workflows/
      ├─ test.yml
      └─ workflow.yml

License

MIT License – feel free to use, modify, and contribute.

Release files for dotenvcheck 0.1.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for dotenvcheck 0.1.9
File Size Uploaded
dotenvcheck-0.1.9.tar.gz 7.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for dotenvcheck 0.1.9
File Interpreter ABI Platform
dotenvcheck-0.1.9-py3-none-any.whl Python 3 none any Details

Total release size: 17.3 kB

Release files / dotenvcheck-0.1.9.tar.gz

Download URL dotenvcheck-0.1.9.tar.gz
Size 7.4 kB
Tags Source
SHA-256 checksum
How to use checksums
36bd6474b9cbe9248d9d45d2cd9074d9690ca0e251682533ba478e0ea02c9a30
BLAKE2b-256 checksum
How to use checksums
21627265a7e561f837cadbc17dc98424222558930698d50dc9f27ad913c79bb1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 23, 2025.

Transparency log

Release files / dotenvcheck-0.1.9-py3-none-any.whl

Download URL dotenvcheck-0.1.9-py3-none-any.whl
Size 9.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
58af6b1c90e387ce88d2cabdce6ac20a4bbc0f761fd8ecc90cad39154774b712
BLAKE2b-256 checksum
How to use checksums
85f1a9018a6393cb1a029f5d67180ff2582f717392ae1b6e7b8ba733ee7b7710
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 23, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.9 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page