Key facts
- Plain text with one KEY=value per line; # starts a comment, and values with spaces or # should be quoted.
- There is no formal standard, so quoting, multi-line values and ${VAR} expansion differ between libraries.
- Names starting with a dot are hidden by default in Finder, Linux file managers and many FTP clients.
- Usually paired with a committed .env.example listing the required keys without real values.
- Most loaders do not override variables already set in the real environment, and some frameworks cache config, so edits may not appear until a restart or cache clear.
How to open a .env file
Open it in VS Code or Notepad (choose 'All files' in the Open dialog). Name new files .env. in Explorer, or create them from the editor, because Explorer may refuse a name that starts with a dot.
Press Cmd+Shift+. in Finder to show hidden files, then open it in a code editor, or run open -e .env in Terminal.
Use ls -a to see it and nano .env or vim .env to edit; in file managers press Ctrl+H to show hidden files.
Common problems and fixes
- Variables are undefined or still show old values
- The app is reading from a different directory, the variable is already set in the shell or server, or config is cached. Restart the process and clear caches, for example php artisan config:clear in Laravel.
- Values with spaces, # or quotes are cut off
- Unquoted # starts a comment and spaces can end the value in some parsers. Wrap such values in double quotes and escape inner quotes.
- .env is downloadable from the website
- The file sits inside the public web root, so anyone can request /.env. Move it above the document root or block it in .htaccess or the Nginx config, and rotate every exposed secret immediately.
- Secrets were committed to Git
- Deleting the file in a new commit does not remove it from history. Rotate the keys first, add .env to .gitignore, then purge it from history with git filter-repo if needed.
- "KEY=value" lines fail after editing on Windows
- Some loaders choke on CRLF line endings or a UTF-8 BOM. Save the file as UTF-8 without BOM with LF line endings.
Often converted to or from: JSON, YAML, INI, Docker Compose environment block