dotenv

Loads environment variables from a .env file into process.env for Node.js apps.

Library
npm
v18.0.4
20,543 stars
BSD-2-Clause

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
78 /100 Good
Development Activity 96
Maintenance 52
Community 64
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
83 /100 Excellent
Architecture 78
Code Quality 88
Innovation 72
Learning Curve 95

dotenv is a zero-dependency Node.js module that loads environment variables from a .env file into process.env, following the twelve-factor app methodology of keeping configuration separate from code. It has been the de facto standard for local environment configuration in the Node.js ecosystem since 2013, used by hundreds of thousands of projects to keep API keys, database URLs, and other secrets out of source control while still making them easy to access at runtime.

The library exposes a tiny, stable API: require('dotenv').config() (or import 'dotenv/config' for ESM) parses a .env file and populates process.env, plus a standalone parse() function for programmatic use and a dotenv run -- CLI for injecting variables into any child process without modifying application code.

What You Get

  • A config() function that reads .env and populates process.env in one call
  • A standalone parse() function for turning a string or Buffer of env-style text into a plain object without touching process.env
  • A populate() function for merging parsed values into any target object, with optional override behavior
  • A dotenv run -- <command> CLI for injecting .env variables into a child process without any code changes
  • Support for multiline values (e.g. PEM private keys), inline comments, quoted strings, and multiple .env files via -f/options.path

Common Use Cases

  • Loading local development secrets (API keys, database URLs) without committing them to version control
  • Configuring 12-factor apps where the same codebase runs against different environments via different .env files
  • Injecting environment variables into a script or test run with dotenv run -- node script.js without editing the script
  • Parsing arbitrary env-formatted text (e.g. from a secrets manager) into a plain object with dotenv.parse()

Under The Hood

Architecture dotenv’s execution path is deliberately linear: config() resolves a .env path (or array of paths), reads each file synchronously with fs.readFileSync, and hands the raw text to parse(), a single regex-driven state machine (lib/main.js) that walks each line, strips surrounding quotes, and expands escaped newlines only inside double-quoted values. The parsed key/value map is then merged onto process.env (or a caller-supplied processEnv) by populate(), which enforces the override-vs-preserve policy and returns only the keys it actually wrote. cli.js reuses parse()/populate() directly rather than duplicating logic, so the CLI and the library share one code path end to end.

Tech Stack The package is pure CommonJS JavaScript with a companion .d.ts for TypeScript consumers (lib/main.d.ts) and has zero runtime dependencies — fs, path, and os from Node core are the only imports. package.json declares engines.node >= 12 and ships dual entry points (require('dotenv') and dotenv/config for side-effect-style imports), with standard for linting and tap for the test runner in devDependencies.

Code Quality The tests/ directory contains six focused suites (test-parse.js, test-populate.js, test-config.js, test-config-import.js, test-parse-multiline.js, test-cli.js, ~950 lines total) covering the parser’s quoting/comment/multiline edge cases, override semantics in populate(), and CLI argument parsing including error paths like a missing -f value. Error handling is explicit and typed via err.code = 'OBJECT_REQUIRED' rather than throwing bare Errors, and the configDotenv() function accumulates lastError across multiple file paths instead of failing fast, favoring partial success over hard failure.

API Design The public surface is intentionally minimal — four functions (config, configDotenv, parse, populate) cover every use case, and the single most common call, require('dotenv').config(), requires no arguments and no boilerplate. Optional behavior (custom path, encoding, override, debug/quiet output) is exposed through a single options object rather than a proliferation of methods, and the same options can be set via DOTENV_CONFIG_* environment variables for zero-code CLI configuration, which keeps the day-to-day API surface small while still supporting advanced setups.

Used by 227 apps in this directory

Java
46%
Other

Stirling PDF

Digital Signiture · Productivity

93,148

The open-source PDF platform you can run anywhere — edit, convert, sign, and automate PDFs without sending files to external servers.

View details
92
Repo Health
86
Technical
71
Dependency
Built with
Java 46%
TypeScript 45%
Updated 1 weeks ago
Go
65%
GPL 3.0

Stormkit

Devops · Hosting Control Panel

262

Self-hostable platform for deploying and hosting modern web apps with automated CI/CD, custom domains, and a built-in serverless runtime — a true open-source alternative to Vercel and Netlify.

View details
79
Repo Health
79
Technical
67
Dependency
Built with
Go 65%
TypeScript 32%
Updated 1 weeks ago
TypeScript
88%
Other

strapi

CMS

73,243

Open-source headless CMS that auto-generates REST and GraphQL APIs from your content models, with a fully customizable admin panel you control.

View details
93
Repo Health
84
Technical
66
Dependency
Built with
TypeScript 88%
JavaScript 12%
Updated 1 weeks ago
TypeScript
95%
Other

Suna

AI Agents

20,238

Turn your company into a git repo — one config, one command center, a workforce of AI agents that runs the real work around the clock.

View details
90
Repo Health
79
Technical
66
Dependency
Built with
TypeScript 95%
Updated 1 weeks ago
TypeScript
72%
Apache 2.0

Supabase

Authentication · Databases · Developer Tools

110,828

The open-source Postgres development platform that replaces Firebase with authentication, real-time APIs, edge functions, storage, and vector embeddings — all built on PostgreSQL.

View details
90
Repo Health
91
Technical
62
Dependency
Built with
TypeScript 72%
MDX 26%
Updated 1 weeks ago
TypeScript
91%
MIT

Super Productivity

Productivity · Project Management

22,309

A privacy-respecting, local-first task manager with built-in timeboxing, Pomodoro timer, and deep integrations for Jira, GitHub, GitLab, and CalDAV — no accounts, no data collection, ever.

View details
91
Repo Health
81
Technical
72
Dependency
Built with
TypeScript 91%
Updated 1 weeks ago
TypeScript
54%
MIT

Superagent

AI Agents · Security

6,757

An open-source SDK that blocks prompt injections, redacts PII and secrets, scans repositories for AI-targeted attacks, and red-teams production agents.

View details
69
Repo Health
66
Technical
74
Dependency
Built with
TypeScript 54%
Python 43%
Updated 1 months ago
TypeScript
96%
Other

superglue

AI Agents · Data Engineering · Developer Tools

2,063

superglue is an AI-agent-driven integration engine that turns plain-English descriptions of enterprise systems into production-grade API tools, ERP/CRM connectors, and data pipelines — self-hosted or cloud, Y Combinator-backed (W25).

View details
49
Repo Health
79
Technical
67
Dependency
Built with
TypeScript 96%
Updated 1 months ago
TypeScript
98%
Apache 2.0

superlog

AI Agents · Monitoring

1,455

Open-source agentic observability that ingests OpenTelemetry signals, groups them into incidents, and deploys AI agents to investigate and fix your production bugs automatically.

View details
64
Repo Health
73
Technical
73
Dependency
Built with
TypeScript 98%
Updated 2 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers