Skip to content
PN Scripts

Developer tools

Keytally by PN Scripts

A command-line checker that compares .env.example with your real env files by key name only, reports missing, extra, empty and duplicate keys, and never prints a value.

  • Go
  • dotenv files
  • JSON
  • GitHub Actions annotations
  • Coming soon

Coming soon

Not published on its store yet, so there is no buy or download link. PN Scripts does not take payment for it here.

Keytally run without arguments finding .env.example, .env.staging and .env.production and listing errors, warnings and a typo hint

What it solves

The gap

Deployments fail because a new setting was added to .env.example but not to staging or production, and the usual way to compare env files is to open them, which puts secrets on screens and in logs.

What it is

Keytally compares the files by key names only, lists exactly what is missing, extra, empty or duplicated with line numbers, and returns an exit code a CI pipeline can stop on.

How you use it

Catch configuration drift before a deploy without exposing a single secret.

For teams that keep configuration in env files, Keytally is a small, dependency-free check that can run anywhere, including CI logs, because it is built never to output a value.

Who it is for

Use it when

  • A CI step that fails when a deployment env file lacks a key from .env.example
  • Checking staging and production files after adding a new setting
  • Reviewing an env file shared over a screen or a log without revealing its values

Built for

  • Web and backend developers whose projects use .env files
  • DevOps engineers who maintain deployment configuration and CI pipelines

What is inside

What it checks

Run keytally in a project folder and it picks the template (.env.example, .env.sample, .env.template or .env.dist) and checks .env and every .env.* file against it; you can also name the files. Keys in the template but not in a file are errors, keys the template does not know are warnings, empty values are warnings, and keys defined twice or lines that are not KEY=value are errors. Every finding has a line number, missing keys point to the template line, and a likely misspelling in the file is named.

Built never to show a value

Values are looked at only to tell empty from non-empty and are not stored. Syntax errors use fixed descriptions such as missing = or unterminated double quote and name a key only when one can be read safely. A test runs all output formats over fixtures filled with marker values and fails if any marker appears in standard output or standard error.

Output for people and pipelines

The text report groups findings per file with errors first and ends with a one-line result. JSON gives counts, the role of each file and every finding with its kind, key and line. The github format writes workflow commands so each finding appears as an annotation on the right line of the right file.

Your rules for failure

By default only errors fail the run. --strict makes warnings fail too, --empty-is-error is stricter about empty values, --allow-empty and --no-extra switch those checks off, and --ignore leaves out keys by pattern, such as local-only settings. Exit code 1 means problems were found and 2 means the command or a file could not be used.

Specs

Availability
Coming soon
Vendor
PN Scripts
Type
Software
Platforms
Go
Pricing
One-time purchase Price to be announced.
License
Proprietary
Deployment
Download (static binaries for Linux, macOS and Windows, with source code)
Maturity
v1.0.0

Compatibility

Platform or runtime Supported versions Tested up to
Linux amd64 kernel 3.2 (Go 1.26 minimum) or newer Ubuntu 24.04, kernel 6.8
Linux arm64 kernel 3.2 (Go 1.26 minimum) or newer built, not run
macOS arm64 macOS 12 (Go 1.26 minimum) or newer built, not run
Windows amd64 Windows 10 (Go 1.26 minimum) or newer built, not run

Stack

  • Go
  • dotenv files
  • JSON
  • GitHub Actions annotations

Keytally is coming soon

It is finished and tested. It is not on sale yet; this page will say where to get it when it is.

Coming soon

Not published on its store yet, so there is no buy or download link. PN Scripts does not take payment for it here.

Questions

A command-line tool that compares a template such as .env.example with real env files by key names only and reports missing, extra, empty and duplicate keys and malformed lines, without ever printing a value.

Only the binary for your system: Linux amd64 or arm64, macOS on Apple silicon, or Windows amd64. The Linux amd64 build was tested on Ubuntu 24.04; the others were cross-compiled but not run. Building from source needs Go 1.22 or newer.

It does not validate what a value contains, expand ${VAR} references, load variables into the environment or edit your files. There is no Intel macOS binary, although one can be built from the included source, and the binaries are not code-signed.

Keytally is written in Go using only the standard library. Its tests use fixture files whose every value is a fake marker, cover the parser, each kind of finding, file discovery, typo hints, the options, all output formats and the exit codes, and include a leak test that runs 28 combinations of files and options and checks that no marker reaches the output. Created with AI assistance; the parser, the checks and the promise that no value is printed were tested by PN Scripts with automated Go tests on fake fixture files and demo runs on Linux amd64.

It is not on sale yet. When it is, this page will link to the store; PN Scripts does not take payment on this site.