# .env manager & diff — no upload

> Parse, edit, and diff .env files to spot missing or changed variables between environments, in your browser. Nothing is uploaded.

Parse and edit .env files and diff two of them to find missing, added, or changed variables between environments. It runs in the browser, so your environment files — which hold secrets — never leave the tab.

"Works on my machine" is often a missing environment variable. Diffing .env files across environments surfaces the key that's absent or different, without pasting secrets into a random online diff.

Because .env files are basically credential stores, keeping this local is the point. Scan for leaked secrets with the secret scanner, and decode Kubernetes secrets with the k8s secret tool.

## How to

1. **Add .env files.** Paste or drop one or two .env files.
2. **Diff.** Compare them to see missing and changed keys.
3. **Fix & copy.** Align the variables and copy the result.

## FAQ

### How do I find missing env vars between environments?

Diff your local and production .env files here; the tool highlights keys present in one but not the other, the usual cause of an app that works locally but not deployed.

### Does it detect secrets?

Values often are secrets, which is exactly why this runs locally. To actively scan text for exposed credentials, use the secret scanner.

### Is my .env uploaded?

No. Parsing and diffing happen in the browser, so your secrets stay on your device.


## Related tools

- [Secret scanner](https://www.safepaper.app/dev/secret-scanner)
- [K8s secret decode](https://www.safepaper.app/dev/k8s-secret)
- [Config converter](https://www.safepaper.app/dev/config-convert)
- [Text diff](https://www.safepaper.app/dev/text-diff)

---

Canonical HTML: https://www.safepaper.app/dev/env-manager
Markdown: https://www.safepaper.app/dev/env-manager.md

There is no upload endpoint — your files are processed in this browser tab. Open your network tab and check.
