Skip to main content

🛡️ env-sentry

Stop leaking secrets in .env files. Zero dependencies, one command.

PyPI License: MIT Python 3.8+ Zero Dependencies

Every project with a .env file eventually has one of these moments:

  • Someone's .env isn't in .gitignore and real secrets get pushed to GitHub.
  • .env.example drifts out of sync, and a new teammate spends 20 minutes figuring out which env vars they're missing.
  • A Stripe key or AWS credential gets hardcoded "just for testing" and never gets cleaned up.

env-sentry is a tiny CLI that catches all three, in one command, with no dependencies to install.


Install

pip install env-sentry

Quick start

# Scaffold .env.example and make sure .env is git-ignored
env-sentry init

# Compare .env against .env.example, flag drift and leaked secrets
env-sentry check

# Regenerate .env.example from .env (values are redacted, never copied)
env-sentry sync

# Scan the whole repo for hardcoded API keys, tokens, and private keys
env-sentry scan

Example output

$ env-sentry check

❌ Keys in .env but missing from .env.example:
   - STRIPE_SECRET_KEY
   - DATABASE_URL

🚨 .env.example may contain REAL secret values, not placeholders:
   - OLD_API_KEY

🚨 '.env' does not appear to be listed in .gitignore!
   Anyone who commits will leak real secrets. Run `env-sentry init` to fix this.
$ env-sentry scan

config.py:14  AWS Access Key
config.py:14  Suspicious value for 'AWS_SECRET'
notes.txt:3   GitHub Token

🚨 3 potential secret(s) found. Review before committing/pushing.

What it checks for

Command What it does
init Creates .env.example if missing, adds .env to .gitignore
check Diffs .env vs .env.example, flags real secrets accidentally left in the example file, confirms .env is git-ignored
sync Rewrites .env.example from .env's keys with placeholder values — your real secrets never touch the example file
scan Walks the repo looking for AWS keys, GitHub/Slack tokens, Stripe live keys, private key blocks, JWTs, and suspicious KEY=value pairs

Exit codes are non-zero on any issue found, so it's a one-line addition to CI or a pre-commit hook:

# .github/workflows/tests.yml
- run: pip install env-sentry && env-sentry check && env-sentry scan
# pre-commit hook
env-sentry scan || exit 1

Why not just use git-secrets / truffleHog / detect-secrets?

Those are great, heavier tools for deep git-history scanning. env-sentry is intentionally small: it's the 5-second daily check, not a security audit platform. No config file, no dependencies, no setup — just an honest answer to "did I mess up my .env today?"


Contributing

Issues and PRs welcome. The whole tool is a single ~250 line file (env_sentry/cli.py) on purpose — keep it that way.

License

MIT

Metadata

Release files for env-sentry 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for env-sentry 0.1.1
File Size Uploaded
env_sentry-0.1.1.tar.gz 8.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for env-sentry 0.1.1
File Interpreter ABI Platform
env_sentry-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 16.1 kB

Release files / env_sentry-0.1.1.tar.gz

Download URL env_sentry-0.1.1.tar.gz
Size 8.0 kB
Tags Source
SHA-256 checksum
How to use checksums
bda9f3c0d769506425359b976e10b8ecdbbf93af46fb5b9c4776b16cb96fb437
BLAKE2b-256 checksum
How to use checksums
c6885c057705998f504af538f5d978abf3f58132bb7320bdd42d421662ae7a62
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.

Transparency log

Release files / env_sentry-0.1.1-py3-none-any.whl

Download URL env_sentry-0.1.1-py3-none-any.whl
Size 8.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3cd205d254c62196a4c6a63ec336d484454ae9a21cc679659ebcbce00ae2cc45
BLAKE2b-256 checksum
How to use checksums
1af75249e19687d575ea2142592f173682155585068562d7b6d74709125e9e40
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.3

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page