The short answer
Your .env file is on your computer. The server only has the variables that were saved for it. If process.env.SOMETHING is undefined online, either it was never saved, it was saved after the app started, or it is read at build time. Ask your agent to list the variable names that are set, and compare them with the ones your code reads.
Five checks
-
Is the variable set?
Ask your agent: "Which environment variables are set for this app?" Your agent can list the names, never the values. If yours is not there, set it.
-
Did you redeploy after you set it?
The running app keeps its old values until the next deploy. A redeploy builds the last version again with the current variables, without sending the code again.
-
Is it read at build time?
Variables you save are available when the app runs, not while the image is being built. A value a frontend reads during the build, such as a
NEXT_PUBLIC_orVITE_variable, is copied into the built files, so it must be set before the build. See environment variables and secrets. -
Is the name spelled the same?
STRIPE_SECRET_KEYandSTRIPE_SECRETare different variables. Names are case-sensitive. -
Does the platform already set it?
Antideploy sets
DATABASE_URL, the bucket, sign-in and email variables, your app's own address and some signing secrets for you. A copy that you set yourself wins, so a wrong copy can hide the right one.
Browser code cannot read server variables
A frontend only sees variables that its build copies in, such as NEXT_PUBLIC_ and VITE_ ones. A plain process.env.SECRET in browser code is undefined, on purpose. Never put a secret in a public variable.