api/v2/… only. Fields are optional; unknown names are ignored by the API.
Pick a community for each side and run the comparison. Both sides authenticate with their API key, then read api/v2/organization with the full requested-fields set.
Settings that differ are flagged, so a target environment can be configured to match a source.