🛡️ env-sentry
Stop leaking secrets in .env files. Zero dependencies, one command.
Every project with a .env file eventually has one of these moments:
- Someone's
.envisn't in.gitignoreand real secrets get pushed to GitHub. .env.exampledrifts out of sync, and a new teammate spends 20 minutes figuring out which env vars they're missing.- A Stripe key or AWS credential gets hardcoded "just for testing" and never gets cleaned up.
env-sentry is a tiny CLI that catches all three, in one command, with no dependencies to install.
Install
pip install env-sentry
Quick start
# Scaffold .env.example and make sure .env is git-ignored
env-sentry init
# Compare .env against .env.example, flag drift and leaked secrets
env-sentry check
# Regenerate .env.example from .env (values are redacted, never copied)
env-sentry sync
# Scan the whole repo for hardcoded API keys, tokens, and private keys
env-sentry scan
Example output
$ env-sentry check
❌ Keys in .env but missing from .env.example:
- STRIPE_SECRET_KEY
- DATABASE_URL
🚨 .env.example may contain REAL secret values, not placeholders:
- OLD_API_KEY
🚨 '.env' does not appear to be listed in .gitignore!
Anyone who commits will leak real secrets. Run `env-sentry init` to fix this.
$ env-sentry scan
config.py:14 AWS Access Key
config.py:14 Suspicious value for 'AWS_SECRET'
notes.txt:3 GitHub Token
🚨 3 potential secret(s) found. Review before committing/pushing.
What it checks for
| Command | What it does |
|---|---|
init |
Creates .env.example if missing, adds .env to .gitignore |
check |
Diffs .env vs .env.example, flags real secrets accidentally left in the example file, confirms .env is git-ignored |
sync |
Rewrites .env.example from .env's keys with placeholder values — your real secrets never touch the example file |
scan |
Walks the repo looking for AWS keys, GitHub/Slack tokens, Stripe live keys, private key blocks, JWTs, and suspicious KEY=value pairs |
Exit codes are non-zero on any issue found, so it's a one-line addition to CI or a pre-commit hook:
# .github/workflows/tests.yml
- run: pip install env-sentry && env-sentry check && env-sentry scan
# pre-commit hook
env-sentry scan || exit 1
Why not just use git-secrets / truffleHog / detect-secrets?
Those are great, heavier tools for deep git-history scanning. env-sentry is intentionally small: it's the 5-second daily check, not a security audit platform. No config file, no dependencies, no setup — just an honest answer to "did I mess up my .env today?"
Contributing
Issues and PRs welcome. The whole tool is a single ~250 line file (env_sentry/cli.py) on purpose — keep it that way.
License
MIT
Metadata
Release files for env-sentry 0.1.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| env_sentry-0.1.1.tar.gz | 8.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| env_sentry-0.1.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 16.1 kB
Release files / env_sentry-0.1.1.tar.gz
| Download URL | env_sentry-0.1.1.tar.gz |
|---|---|
| Size | 8.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bda9f3c0d769506425359b976e10b8ecdbbf93af46fb5b9c4776b16cb96fb437
|
|
BLAKE2b-256 checksum How to use checksums |
c6885c057705998f504af538f5d978abf3f58132bb7320bdd42d421662ae7a62
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.
Transparency logRelease files / env_sentry-0.1.1-py3-none-any.whl
| Download URL | env_sentry-0.1.1-py3-none-any.whl |
|---|---|
| Size | 8.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3cd205d254c62196a4c6a63ec336d484454ae9a21cc679659ebcbce00ae2cc45
|
|
BLAKE2b-256 checksum How to use checksums |
1af75249e19687d575ea2142592f173682155585068562d7b6d74709125e9e40
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.
Transparency log