Docs

Environment variables

Settings and secrets your app reads at runtime — database URLs, API keys, SMTP passwords — kept out of your repository.

Adding variables

Open your project and find Environment variables. Add a row per variable with Add variable, then press Save. Names are uppercased as you type.

Paste a .env file

Choose Paste .env and paste the contents of a local .env file, then Import. The importer understands the usual shapes:

# Comments and blank lines are ignored
DATABASE_URL=postgres://shop:secret@db.example.com:5432/shop
export SMTP_PASSWORD="quoted values are fine"
RAZORPAY_KEY_ID='single quotes too'
NEXT_PUBLIC_SITE_URL=https://www.yourshop.in

A pasted variable replaces an existing one with the same name. Nothing is saved until you press Save.

When changes take effect

Saved values are used from the next deploy. The running app keeps the environment it started with, so redeploy after changing a variable.

How your app receives them

At deploy time, every variable is:

  • written to a .env file in your app's directory (or its root directory, if you set one), readable only by the app's user, and
  • exported into the environment the install, build and start commands run with.

So both process.env.DATABASE_URL and libraries that load .env files (such as dotenv) work. Variables are available during the build too, which matters for frameworks that read configuration at build time.

PORT is set by Kernel6 when your app starts; your app should listen on it.

How they are stored

  • Encrypted at rest with AES-256-GCM, each value with its own random nonce.
  • Masked in the dashboard. Values load hidden and are shown only when you reveal one, so a screen share does not expose your keys.
  • Decrypted only to deploy. Values never appear in the deploy script as text; they travel encoded, so quotes or $ signs in a password cannot change what the script does.

Rules and limits

RuleLimit
NameLetters, digits and underscores; must not start with a digit; up to 64 characters
Value lengthUp to 4,096 characters
Line breaksNot allowed in values. Store multi-line values such as private keys base64-encoded and decode them in your app.
CountUp to 100 variables per project
DuplicatesEach name may appear once

Good practice

  • Keep real values out of Git. Commit a .env.example with names only, and add .env to .gitignore.
  • In Next.js, anything prefixed NEXT_PUBLIC_ is built into code sent to browsers. Never put a real secret behind that prefix.
  • If a secret was ever committed, rotate it at the provider — removing it from the code does not remove it from Git history.

More on this in Keep your secrets out of your Git repository.