.env files are the most common source of silent setup failures. An app that crashes with undefined is not a function or connection refused is often missing an env key that was added by a teammate and never propagated.
- A teammate adds
REDIS_URLto the app and to CI secrets. - They add it to
.env.examplewith a blank value. - Other teammates pull the branch, run the app, and get a cryptic error.
- Twenty minutes later: "Oh, you need to add REDIS_URL to your .env."
Snagify compares .env.example against .env and reports missing keys — without ever reading actual values.
snagify check.env 3 required keys missing
Likely blockers:
• Required env keys are absent: DATABASE_URL, JWT_SECRET, REDIS_URL
snagify init classifies keys from .env.example automatically:
| Classification | Trigger | Missing = |
|---|---|---|
required |
blank value + sensitive name (API_KEY, TOKEN, SECRET, etc.) | Critical blocker |
recommended |
concrete default (MAX_RETRIES=3) or tuning name | Warning |
optional |
disabled feature group (FALLBACK_1_ENABLED=false) | Silent |
Example .env.example:
DATABASE_URL=
JWT_SECRET=
MAX_RETRIES=3
TIMEOUT_MS=5000
FALLBACK_1_ENABLED=false
FALLBACK_1_API_KEY=
FALLBACK_1_MODEL=Result after snagify init:
env:
required:
- DATABASE_URL
- JWT_SECRET
recommended:
- MAX_RETRIES
- TIMEOUT_MS
optional:
- FALLBACK_1_ENABLED
- FALLBACK_1_API_KEY
- FALLBACK_1_MODELThe fallback provider's API key is optional because FALLBACK_1_ENABLED=false in .env.example.
Override heuristics with a comment on the line before:
# optional
ANALYTICS_API_KEY=
# required
PAYMENT_SECRET=- Never reads actual
.envvalues - Never prints secret values
- Never stores or transmits credentials
snagify fix --safe # create .env from .env.example / append missing keys
snagify fix --safe --dry-run # preview without applyingSafe fix creates .env from .env.example and appends blank placeholders for missing required keys. You still need to set real values.