The short answer
To set an environment variable, tell your connected coding agent the name and the value, or tell it to use the values in your .env file. They go into an encrypted store. From then on they are write-only: you can see which names are set, but nobody, including your agent, can read a value back. To apply a change, redeploy. Antideploy fills in some variables for you, so you only supply what is really yours.
Say this to your coding agent
Set STRIPE_SECRET_KEY from my .env file and redeploy.
If your agent is not connected yet, paste this first: Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
What happens to your .env file
A .env file in your project is read when you deploy, so you do not retype keys you already have. The values go into the encrypted store, and the file itself is dropped from the build. Move the file first if that is not what you want. Blank values, placeholders and PORT are ignored.
What Antideploy sets for you
Do not copy these into the secrets store. The platform sets them in the running app, and a copy could shadow the real ones.
-
DATABASE_URLandPG*, when your app has a Postgres database. -
AWS_*,BUCKET_NAMEandS3_*, when your app has a bucket. -
NEON_AUTH_*andVITE_NEON_AUTH_URL, when sign-in is on. -
RESEND_API_KEY,RESEND_BASE_URL,RESEND_API_URLandEMAIL_FROM, when email is on. -
OPENROUTER_API_KEY, when you create an AI key for the app. -
APP_URL,SITE_URL,NEXTAUTH_URLand theNEXT_PUBLIC_andVITE_pairs for your address, on every deploy. -
JWT_SECRET,SESSION_SECRET,SECRET_KEY,AUTH_SECRETandNEXTAUTH_SECRET, generated if your code reads them. Different for every app and the same on every deploy.
A value you set yourself always wins.
How a change reaches the app
The running app keeps its old values until the next deploy. A redeploy builds the version last sent again with the current variables, without sending the code again. Removing a variable works the same way: the running app keeps it until the next deploy.
The build-time trap
Variables you save on Antideploy are available when your app runs, not while it builds. Some values are read during the build, such as a variable starting with NEXT_PUBLIC_ or VITE_. They are copied into the built files, so they must be set before the build, and they are visible to anyone who loads your site. Never put a secret in one.
If a framework reads a secret while it builds and the build fails, give the value a fallback, or read it inside a handler instead of at the top of a file. See Failed to collect page data.