BlogVariables

How to set environment variables and secrets.

Your keys go into an encrypted store and are write-only from then on. Antideploy fills in the ones that are not yours to supply.

How the Agent API works
  • EncryptedFrom the moment they are saved
  • Write-onlyNot even your agent can read a value
  • Some are set for youDATABASE_URL, your address, signing secrets
  • A redeploy applies a changeNo need to send the code again

The short answer

To set an environment variable, tell your connected coding agent the name and the value, or tell it to use the values in your .env file. They go into an encrypted store. From then on they are write-only: you can see which names are set, but nobody, including your agent, can read a value back. To apply a change, redeploy. Antideploy fills in some variables for you, so you only supply what is really yours.

Say this to your coding agent

Set STRIPE_SECRET_KEY from my .env file and redeploy.

If your agent is not connected yet, paste this first: Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

What happens to your .env file

A .env file in your project is read when you deploy, so you do not retype keys you already have. The values go into the encrypted store, and the file itself is dropped from the build. Move the file first if that is not what you want. Blank values, placeholders and PORT are ignored.

What Antideploy sets for you

Do not copy these into the secrets store. The platform sets them in the running app, and a copy could shadow the real ones.

  • DATABASE_URL and PG*, when your app has a Postgres database.
  • AWS_*, BUCKET_NAME and S3_*, when your app has a bucket.
  • NEON_AUTH_* and VITE_NEON_AUTH_URL, when sign-in is on.
  • RESEND_API_KEY, RESEND_BASE_URL, RESEND_API_URL and EMAIL_FROM, when email is on.
  • OPENROUTER_API_KEY, when you create an AI key for the app.
  • APP_URL, SITE_URL, NEXTAUTH_URL and the NEXT_PUBLIC_ and VITE_ pairs for your address, on every deploy.
  • JWT_SECRET, SESSION_SECRET, SECRET_KEY, AUTH_SECRET and NEXTAUTH_SECRET, generated if your code reads them. Different for every app and the same on every deploy.

A value you set yourself always wins.

How a change reaches the app

The running app keeps its old values until the next deploy. A redeploy builds the version last sent again with the current variables, without sending the code again. Removing a variable works the same way: the running app keeps it until the next deploy.

The build-time trap

Variables you save on Antideploy are available when your app runs, not while it builds. Some values are read during the build, such as a variable starting with NEXT_PUBLIC_ or VITE_. They are copied into the built files, so they must be set before the build, and they are visible to anyone who loads your site. Never put a secret in one.

If a framework reads a secret while it builds and the build fails, give the value a fallback, or read it inside a handler instead of at the top of a file. See Failed to collect page data.

01Before you commit

Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

  1. The disk forgets

    Anything written to local disk is gone on the next deploy. Apps that speak S3 get a bucket instead.

02Questions

Variable questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Can I see a value after I save it?

No. The console shows which variables are set and when they changed, never what is in them. If you lose a value, set it again.

Can my agent read my secrets?

No. It can set variables and list their names, and nothing else. A leaked key cannot be used to read the credentials it wrote.

Is there a history of changes?

Yes. The console records each variable added, changed or removed, and a deploy lists the changes since the last version that went live. Names only, never values.

Which variables can I not remove?

The ones the platform supplies. To use your own value, set the variable yourself and it wins.

Should I put secrets in my code?

Never. Keep them in environment variables, and keep your .env out of Git.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.