Home/Tools/Client-Side .env Sanitizer
100% In-Browser Privacy • Zero Data Sent to Servers

Client-Side .env Sanitizer & Secret Leak Checker

AI editors frequently prepend NEXT_PUBLIC_ to private keys just to silence client undefined errors. Audit your environment variables client-side and generate a clean .env.example with dummy placeholders.

Complete Privacy Guarantee: This analysis runs strictly in your browser using JavaScript. No tokens, passwords, or files are ever sent to our servers.
Paste your .env or .env.local11 variables detected

The NEXT_PUBLIC_ Trap

When you ask an AI assistant to fetch user data or create a checkout session from a client component, it encounters a build error saying process.env.STRIPE_SECRET_KEY is undefined. Its quickest solution? Prefix it with NEXT_PUBLIC_.

Next.js then bakes that live key directly into the compiled JavaScript bundle. Anyone who opens Chrome DevTools can read your secret key in plain text.

3 Critical Leaks & 1 Warnings

Immediate fixes required before committing or pushing code.

Safe to commit to GitHub as: .env.example
# Project environment variables (vibe coded app)
NODE_ENV=your_node_env_here
PORT=your_port_here

# Next.js Public Keys
NEXT_PUBLIC_APP_URL=your_app_url_here
NEXT_PUBLIC_SUPABASE_URL=your_supabase_url_here
NEXT_PUBLIC_SUPABASE_ANON_KEY=your_supabase_anon_key_here

# CRITICAL BUG: AI added NEXT_PUBLIC_ to private secrets so client code could read them!
NEXT_PUBLIC_STRIPE_SECRET_KEY=sk_live_...
NEXT_PUBLIC_SUPABASE_SERVICE_ROLE_KEY=your_supabase_service_role_key

# Database connection string with raw password
DATABASE_URL=postgresql://user:password@localhost:5432/dbname

# AI Provider API Keys
OPENAI_API_KEY=sk-proj-...
ANTHROPIC_API_KEY=sk-ant-...

# Stripe Webhook Secret
STRIPE_WEBHOOK_SECRET=your_stripe_webhook_secret_here
Did you already commit a secret in past commits?

Even if you delete a key from your current file, it still lives in your Git history. Attackers scan commit histories with bots. The Founder Pass ($15 one-time) scans your entire repository history and code files for lingering secrets.