# Secrets and environment

> Keep API keys and settings out of your code. Store them per environment in Settings, and your Cloud app reads them from its environment.
> Source: https://playcode.io/docs/publish/secrets-and-environment - last reviewed 2026-10-09.
> Ask Playcode's agent: "Set up the environment variables this app needs and tell me which secrets I should add." It sets plain variables and names the secrets you need; paste secret values in Settings yourself, so they stay out of the chat history.

A Cloud app reads its settings and secrets, like an API key, from its environment. You manage them in **Settings**, **Secrets**, separately for **Development** and **Production**; a value marked **Secret** is stored encrypted and shown masked.

## Do it yourself

1. In the project, open **Settings** and choose **Secrets** under the project.
2. In **Development** or **Production**, type the name, like `RESEND_API_KEY`, and the value.
3. For a key, password or token, turn on **Secret**.
4. Choose **Add**. Development applies the change to the running app in seconds: "Applied - your app picked up the change."
5. In **Production**, choose how to apply it. **Apply now - restarts your app** restarts the app for a moment and it reads the new value. **At next publish** saves the value without restarting the app.
6. To use a development value in production too, open the row's menu and choose **Copy to Production**.

To add many values at once, choose **Paste a block**, paste `KEY=value` lines, mark the secrets, and choose **Import**.

Your code reads a value by its name, for example `process.env.RESEND_API_KEY` in the backend.

> [!IMPORTANT]
> Production keeps its own values: nothing copies from Development by itself. **Production** unlocks after your first publish.

> [!TIP]
> Type secret values in Settings, not in the chat. A value written in the chat stays in the chat's history.

## If it doesn't work

### "Overridden by .env.local - the file value wins until you remove that line."

The project's `.env.local` file sets the same name, and the file wins. Remove that line from the file, or ask the agent to remove it.

### Production does not see a new value

You chose **At next publish**, so the value is saved but the running app may not have it yet. Save the value again and choose **Apply now - restarts your app**, or ask the agent to apply the stored production values: it delivers all of them with one short restart.

### "Names are UPPER_SNAKE_CASE: letters, digits, and underscores, not starting with a digit."

Rename the variable, for example `stripe-key` to `STRIPE_KEY`.

### "Couldn't save the variable. Try again."

Check the limits below. A name that Playcode keeps for itself, or a value that is too long, is refused.

### A row says Managed

"set by Playcode": the platform owns this value, so the row has no menu. You cannot change or delete it.

## Limits

- Up to 64 of your variables in each environment. A value can be up to 8,192 bytes and a name up to 128 characters. All variables of one environment together, Playcode's included, can be up to 32 KB.
- In Settings, a value is one line.
- Names starting with `PLAYCODE_` or `SKY_` are kept for Playcode, and so are `PATH`, `HOME`, `USER`, `SHELL`, `LANG`, `PORT`, `NODE_ENV`, `LD_PRELOAD` and `LD_LIBRARY_PATH`.
- Restoring a checkpoint does not change secrets: they are stored apart from the computer's disk.
- **Settings**, **Secret key** shows the app's key for Playcode services, `PLAYCODE_SECRET_KEY`. It is already in the app's environment. Copy it only for a server of your own, and choose **Rotate** if it leaks: the app restarts on the new key.
- A static site has no server, so it cannot keep a secret: everything in its code reaches the visitor's browser.
