🛡️ env-sentry
Stop leaking secrets in .env files. Zero dependencies, one command.
Every project with a .env file eventually has one of these moments:
- Someone's
.envisn't in.gitignoreand real secrets get pushed to GitHub. .env.exampledrifts out of sync, and a new teammate spends 20 minutes figuring out which env vars they're missing.- A Stripe key or AWS credential gets hardcoded "just for testing" and never gets cleaned up.
env-sentry is a tiny CLI that catches all three, in one command, with no dependencies to install.
Install
pip install env-sentry
Quick start
# Scaffold .env.example and make sure .env is git-ignored
env-sentry init
# Compare .env against .env.example, flag drift and leaked secrets
env-sentry check
# Regenerate .env.example from .env (values are redacted, never copied)
env-sentry sync
# Scan the whole repo for hardcoded API keys, tokens, and private keys
env-sentry scan
Example output
$ env-sentry check
❌ Keys in .env but missing from .env.example:
- STRIPE_SECRET_KEY
- DATABASE_URL
🚨 .env.example may contain REAL secret values, not placeholders:
- OLD_API_KEY
🚨 '.env' does not appear to be listed in .gitignore!
Anyone who commits will leak real secrets. Run `env-sentry init` to fix this.
$ env-sentry scan
config.py:14 AWS Access Key
config.py:14 Suspicious value for 'AWS_SECRET'
notes.txt:3 GitHub Token
🚨 3 potential secret(s) found. Review before committing/pushing.
What it checks for
| Command | What it does |
|---|---|
init |
Creates .env.example if missing, adds .env to .gitignore |
check |
Diffs .env vs .env.example, flags real secrets accidentally left in the example file, confirms .env is git-ignored |
sync |
Rewrites .env.example from .env's keys with placeholder values — your real secrets never touch the example file |
scan |
Walks the repo looking for AWS keys, GitHub/Slack tokens, Stripe live keys, private key blocks, JWTs, and suspicious KEY=value pairs |
Exit codes are non-zero on any issue found, so it's a one-line addition to CI or a pre-commit hook:
# .github/workflows/tests.yml
- run: pip install env-sentry && env-sentry check && env-sentry scan
# pre-commit hook
env-sentry scan || exit 1
Why not just use git-secrets / truffleHog / detect-secrets?
Those are great, heavier tools for deep git-history scanning. env-sentry is intentionally small: it's the 5-second daily check, not a security audit platform. No config file, no dependencies, no setup — just an honest answer to "did I mess up my .env today?"
"env-sentry is not recognized as a command"
This happens when pip installs the executable into a folder that isn't on your system PATH yet — pip usually warns you about this during install (WARNING: The script env-sentry.exe is installed in '...' which is not on PATH).
Quick workaround (works immediately, no setup):
python -m env_sentry.cli --version
Use python -m env_sentry.cli <command> in place of env-sentry <command> any time.
Permanent fix on Windows:
- Copy the exact folder path from pip's warning message (something like
C:\Users\<you>\AppData\Local\Python\pythoncore-3.x\Scripts) - Press the Windows key, search "Edit environment variables for your account", open it
- Under User variables, select Path → Edit → New → paste the folder path → OK on everything
- Close every open terminal window completely (not just the tab — PATH only reloads for new windows)
- Open a fresh terminal and run
env-sentry --version— it should now work directly
Permanent fix on macOS/Linux:
Add pip's user script directory to your shell profile (~/.zshrc, ~/.bashrc, etc.):
export PATH="$HOME/.local/bin:$PATH"
Then run source ~/.zshrc (or restart your terminal).
Changelog
- 0.1.3 —
--versionnow shows the author;checkrespects a custom--envpath when checking.gitignoreinstead of always assuming.env - 0.1.2 —
checkno longer claims things are "in sync" when.envdoesn't exist yet - 0.1.1 — Fixed false positives on token-count variables (
max_tokens,use_token, etc.) and on env-var lookups likeos.environ.get("API_KEY")— only real hardcoded string literals get flagged now - 0.1.0 — Initial release:
init,check,sync,scan
Contributing
Issues and PRs welcome. The whole tool is a single ~250 line file (env_sentry/cli.py) on purpose — keep it that way.
License
MIT
Built by Nour Yahyaoui.
Metadata
Release files for env-sentry 0.1.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| env_sentry-0.1.3.tar.gz | 9.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| env_sentry-0.1.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 18.5 kB
Release files / env_sentry-0.1.3.tar.gz
| Download URL | env_sentry-0.1.3.tar.gz |
|---|---|
| Size | 9.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
56ef63334565ddeebdf78f48e3d563deb95d060545d32d2bb6420f1506da001f
|
|
BLAKE2b-256 checksum How to use checksums |
fc1a0033c8e1f22aabdafe2f11d90fc191235004c756f14dcef166f7e4c105d0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.
Transparency logRelease files / env_sentry-0.1.3-py3-none-any.whl
| Download URL | env_sentry-0.1.3-py3-none-any.whl |
|---|---|
| Size | 9.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8f395d47418a7055c3040290e68aa1667faabebff43e65972f11bb53a6f856c9
|
|
BLAKE2b-256 checksum How to use checksums |
4b47294b5a864267cc5a115c3082add1f6164e7995811069ba81095e8c4e6408
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 16, 2026.
Transparency log