Dotenv Scanner
Dotenv Scanner helps you keep environment variables in your JavaScript and TypeScript projects in sync with your .env files. It scans variable references in source files and definitions in .env files, then shows problems directly in VS Code.
Environment variable mistakes are easy to miss during development: code can refer to a variable that was never added to a .env file, while an old .env entry can remain after the code stops using it. Dotenv Scanner makes both cases visible where you work, so you can find missing configuration and clean up unused entries before they cause confusion.
What it reports
| Problem |
Where it appears |
Default severity |
A source file references a variable that is not defined in any workspace .env file |
On the reference's line in the source file |
Error |
A variable defined in a .env file is not referenced by a scanned source file |
On the definition's line in the .env file |
Warning |
For example, if your code contains process.env.API_URL but no scanned .env file defines API_URL, the source file gets an error. If a .env file defines OLD_TOKEN and no scanned source file uses it, the .env file gets a warning.
The scanner recognizes process.env.NAME and import.meta.env.NAME, including quoted bracket access such as process.env["NAME"]. It reads variable definitions in the form NAME=value or export NAME=value. By default, it scans .js, .jsx, .ts, .tsx, and .mjs source files. Source directories and extensions can be configured.
Getting started
- Install Dotenv Scanner in VS Code and open your project as a workspace.
- Add or open a
.env file and a JavaScript or TypeScript source file. The extension scans the workspace after it activates.
- Open View → Problems (or press
Ctrl+Shift+M on Windows/Linux, Cmd+Shift+M on macOS). Look for diagnostics with the source Dotenv Scanner. Select one to jump to the relevant line.
- Fix the source reference or
.env definition, then save the file. The extension refreshes diagnostics when matching workspace files change.
To run a scan on demand, open the Command Palette (Ctrl+Shift+P or Cmd+Shift+P) and use:
- Scan .env Files — refreshes diagnostics and shows a message listing unused
.env variables.
- Scan Files — refreshes missing-variable diagnostics and shows a message listing variables referenced in source files but missing from
.env files.
The Problems view is the place to see each issue by file and line; the command messages provide a quick summary.
Configuration
Configure Dotenv Scanner in VS Code's Settings UI or your workspace's .vscode/settings.json:
{
"dotenv-scanner.undefinedVariables.directories": ["^src(?:/.*)?$"],
"dotenv-scanner.undefinedVariables.extensions": ["ts", "tsx", "js", "jsx", "mjs"],
"dotenv-scanner.undefinedVariables.severity": "warning"
}
| Setting |
Default |
Purpose |
dotenv-scanner.undefinedVariables.directories |
[".*"] |
Regular expressions matched against workspace-relative source directories. Use .* to scan all directories, including the workspace root. |
dotenv-scanner.undefinedVariables.extensions |
["ts", "tsx", "js", "jsx", ".mjs"] |
Source file extensions to scan. A leading dot is optional. |
dotenv-scanner.undefinedVariables.severity |
"error" |
Severity of missing-variable diagnostics: error, warning, information, or hint. |
The directory and extension settings affect which source files are checked for both missing and unused variables. Unused .env variables are always reported as warnings.
Scope
Dotenv Scanner checks variable names found in files in the open workspace. It supports direct process.env and import.meta.env references; references built dynamically at runtime cannot be resolved by this scan. A variable defined in any scanned .env file counts as defined for the workspace.
Release notes
0.0.1
Initial release: workspace diagnostics for missing and unused environment variables, on-demand scan commands, and configurable source scanning and missing-variable severity.