If you have set up a web app or API project, someone has probably told you to "create a .env file". It is a small text file with a big job: it holds the settings that change between machines, such as database addresses and API keys, outside the code.
What a .env file is
A .env file, often called a dotenv file, is a plain-text list of KEY=value pairs:
DATABASE_URL=postgres://localhost:5432/app
API_KEY=abc123
DEBUG=true
PORT=3000
When the application starts, a library reads the file and loads each pair into the process's environment variables. The code then reads DATABASE_URL from the environment instead of having it written into the source.
The name starts with a dot because on macOS and Linux a leading dot hides a file in normal directory listings. The file is conventionally placed in the project root.
Why environment variables
The idea comes from the Twelve-Factor App methodology, which recommends storing configuration in the environment, strictly separated from code. Settings that differ between development, testing and production should not be edited in the source, and secrets should never be committed to version control. A .env file gives developers a convenient way to set those variables locally without exporting them by hand in every terminal.
Which tools read .env files
The format is a convention, not a standard. The original dotenv library for Node.js popularised it, and equivalents exist for most languages: Python (python-dotenv), Ruby, PHP, Go, Rust and others. Docker Compose can read .env files, and many frameworks, including Next.js, Vite and Laravel, load them automatically. Each implementation has slightly different rules, covered in env file syntax.
What belongs in a .env file
- Database connection strings
- API keys and tokens
- Service URLs that differ per environment
- Feature flags and debug switches
- Ports and hostnames
What does not belong
- Anything that should be committed. A
.envfile with real secrets should stay out of version control. See keeping .env files out of git. - Large or structured data, such as JSON blobs. Values are single-line strings in most implementations.
- Anything you want type-checked. Every value is a string, so
"false"is a non-empty string, and the application must convert it.
A common pattern: .env.example
Because the real file is not committed, projects commonly commit a template named .env.example (or .env.sample) listing the required keys with placeholder values. A new developer copies it to .env and fills in their own values. That way the file documents what the app needs without exposing secrets.
Variants
Projects often have more than one: .env.local, .env.development, .env.production. How they are chosen and which overrides which depends on the framework. See env files for development, staging and production.
How to open and edit a .env file
Because the name begins with a dot, some file managers hide it, and some apps will not let you pick it. Show hidden files in your file manager. The file is plain text, so any editor works. Docento's Text & Markdown Editor opens .env and .env.* files locally in the browser, and checks that each line is a comment or a KEY=value pair with balanced quotes. The file stays on your device, which matters when it holds secrets.
Takeaway
A .env file is a plain-text list of KEY=value settings loaded into an app's environment. It keeps configuration and secrets out of source code, but the file itself should stay out of version control, with a .env.example committed in its place.