# How to set environment variables and secrets.

URL: https://antideploy.com/blog/how-to-set-environment-variables-and-secrets

Your keys go into an encrypted store and are write-only from then on. Antideploy fills in the ones that are not yours to supply.

## At a glance

- **Encrypted**: From the moment they are saved
- **Write-only**: Not even your agent can read a value
- **Some are set for you**: DATABASE_URL, your address, signing secrets
- **A redeploy applies a change**: No need to send the code again

Published 7 October 2026. Facts checked 7 October 2026. 3 min read.

## The short answer

To set an environment variable, tell your connected coding agent the name and the value, or tell it to use the values in your `.env` file. They go into an encrypted store. From then on they are write-only: you can see which names are set, but nobody, including your agent, can read a value back. To apply a change, redeploy. Antideploy fills in some variables for you, so you only supply what is really yours.

> **Say this to your coding agent**
>
> Set STRIPE_SECRET_KEY from my .env file and redeploy.

If your agent is not connected yet, paste this first: Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

## What happens to your .env file

A `.env` file in your project is read when you deploy, so you do not retype keys you already have. The values go into the encrypted store, and the file itself is dropped from the build. Move the file first if that is not what you want. Blank values, placeholders and `PORT` are ignored.

## What Antideploy sets for you

Do not copy these into the secrets store. The platform sets them in the running app, and a copy could shadow the real ones.

- **`DATABASE_URL` and `PG*`**, when your app has a Postgres database.
- **`AWS_*`, `BUCKET_NAME` and `S3_*`**, when your app has a bucket.
- **`NEON_AUTH_*` and `VITE_NEON_AUTH_URL`**, when sign-in is on.
- **`RESEND_API_KEY`, `RESEND_BASE_URL`, `RESEND_API_URL` and `EMAIL_FROM`**, when email is on.
- **`OPENROUTER_API_KEY`**, when you create an AI key for the app.
- **`APP_URL`, `SITE_URL`, `NEXTAUTH_URL` and the `NEXT_PUBLIC_` and `VITE_` pairs for your address**, on every deploy.
- **`JWT_SECRET`, `SESSION_SECRET`, `SECRET_KEY`, `AUTH_SECRET` and `NEXTAUTH_SECRET`**, generated if your code reads them. Different for every app and the same on every deploy.

A value you set yourself always wins.

## How a change reaches the app

The running app keeps its old values until the next deploy. A redeploy builds the version last sent again with the current variables, without sending the code again. Removing a variable works the same way: the running app keeps it until the next deploy.

## The build-time trap

Variables you save on Antideploy are available when your app runs, not while it builds. Some values are read during the build, such as a variable starting with `NEXT_PUBLIC_` or `VITE_`. They are copied into the built files, so they must be set before the build, and they are visible to anyone who loads your site. Never put a secret in one.

If a framework reads a secret while it builds and the build fails, give the value a fallback, or read it inside a handler instead of at the top of a file. See [Failed to collect page data](https://antideploy.com/blog/nextjs-failed-to-collect-page-data).

## Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

### The disk forgets

Anything written to local disk is gone on the next deploy. Apps that speak S3 get a bucket instead.

## Variable questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Can I see a value after I save it?

No. The console shows which variables are set and when they changed, never what is in them. If you lose a value, set it again.

### Can my agent read my secrets?

No. It can set variables and list their names, and nothing else. A leaked key cannot be used to read the credentials it wrote.

### Is there a history of changes?

Yes. The console records each variable added, changed or removed, and a deploy lists the changes since the last version that went live. Names only, never values.

### Which variables can I not remove?

The ones the platform supplies. To use your own value, set the variable yourself and it wins.

### Should I put secrets in my code?

Never. Keep them in environment variables, and keep your `.env` out of Git.

## More guides, and the platform.

Each platform page covers one part of Antideploy: what it does, where it stops and the questions people ask. [See the whole platform](https://antideploy.com/platform), or [all the guides](https://antideploy.com/blog).

- [Why does my app work on localhost but not online?](https://antideploy.com/blog/why-does-my-app-work-on-localhost-but-not-online): Nine common reasons, how to check each one, and how to fix it.
- [How to add AI to your app](https://antideploy.com/blog/how-to-add-ai-to-your-app): One key for hundreds of models, paid from a prepaid wallet in rupees. Your agent creates the key.
- [Failed to collect page data for /api/users](https://antideploy.com/blog/nextjs-failed-to-collect-page-data): A route's code threw during the build. Usually a variable or a database call at the top of a file.

- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Deployments](https://antideploy.com/platform/deployments)
- [Agent API](https://antideploy.com/platform/agent-api)
- [Database](https://antideploy.com/platform/database)

Facts on this page were checked against the live platform on 7 October 2026.

## Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
