About this tool
Turn a real .env into a safe .env.example — values stripped, comments and structure kept, secret keys always blanked.
This tool converts a real .env file into a commit-safe .env.example by stripping every value while preserving keys, comments, blank lines and ordering — the convention documented by dotenv and used across Laravel, Rails and Node starter templates. Keys that match common credential patterns (SECRET, TOKEN, API_KEY, PASSWORD, DSN and similar, drawn from secret-scanner rule sets) are always blanked, and you can optionally keep obviously non-secret values like NODE_ENV or PORT.
Open Env to Example Generator on AltFTool — it loads instantly in your browser.
Paste your code or data sample into the workspace.
Pick the format, conversion, or analysis you need.
Copy the polished result straight back into your project.
Comments, blank lines, ordering and export prefixes survive, so the example file documents itself.
Keys matching credential patterns are blanked even when the keep-non-secret-values option is on.
Choose blank values (KEY=), angle placeholders (KEY=<KEY>) or KEY=changeme to suit your team's convention.
A .env.example is a copy of your .env with the same keys but no secret values, committed to the repository so new developers know which environment variables the app needs. The real .env stays in .gitignore; the example file is safe to share because it contains structure, not credentials.
Keys containing fragments such as SECRET, TOKEN, PASSWORD, API_KEY, PRIVATE, CREDENTIAL, AUTH, DSN, ACCESS_KEY, CLIENT_SECRET, SALT, CERT or WEBHOOK are always stripped, regardless of options. The list mirrors the naming patterns secret scanners like gitleaks flag by default.
Yes — enable the keep-non-secret-values option and well-known configuration keys (NODE_ENV, PORT, LOG_LEVEL, TZ, DEBUG and similar) plus plain boolean or mode values like true, false and production are preserved. Anything matching a secret pattern is still blanked.
No. The conversion runs entirely in your browser with no network requests, so pasted values never leave your machine. Still review the output before committing, since a value can be sensitive even under an innocent-looking key name.