Secrets and environment

A Cloud app reads its settings and secrets, like an API key, from its environment. You manage them in Settings, Secrets, separately for Development and Production; a value marked Secret is stored encrypted and shown masked.

On this page

Ask the agent

Set up the environment variables this app needs and tell me which secrets I should add.

It sets plain variables and names the secrets you need; paste secret values in Settings yourself, so they stay out of the chat history.

Do it yourself

#
  1. In the project, open Settings and choose Secrets under the project.
  2. In Development or Production, type the name, like RESEND_API_KEY, and the value.
  3. For a key, password or token, turn on Secret.
  4. Choose Add. Development applies the change to the running app in seconds: "Applied - your app picked up the change."
  5. In Production, choose how to apply it. Apply now - restarts your app restarts the app for a moment and it reads the new value. At next publish saves the value without restarting the app.
  6. To use a development value in production too, open the row's menu and choose Copy to Production.

To add many values at once, choose Paste a block, paste KEY=value lines, mark the secrets, and choose Import.

Your code reads a value by its name, for example process.env.RESEND_API_KEY in the backend.

If it doesn't work

#

"Overridden by .env.local - the file value wins until you remove that line."

#

The project's .env.local file sets the same name, and the file wins. Remove that line from the file, or ask the agent to remove it.

Production does not see a new value

#

You chose At next publish, so the value is saved but the running app may not have it yet. Save the value again and choose Apply now - restarts your app, or ask the agent to apply the stored production values: it delivers all of them with one short restart.

"Names are UPPER_SNAKE_CASE: letters, digits, and underscores, not starting with a digit."

#

Rename the variable, for example stripe-key to STRIPE_KEY.

"Couldn't save the variable. Try again."

#

Check the limits below. A name that Playcode keeps for itself, or a value that is too long, is refused.

A row says Managed

#

"set by Playcode": the platform owns this value, so the row has no menu. You cannot change or delete it.

Limits

#
  • Up to 64 of your variables in each environment. A value can be up to 8,192 bytes and a name up to 128 characters. All variables of one environment together, Playcode's included, can be up to 32 KB.
  • In Settings, a value is one line.
  • Names starting with PLAYCODE_ or SKY_ are kept for Playcode, and so are PATH, HOME, USER, SHELL, LANG, PORT, NODE_ENV, LD_PRELOAD and LD_LIBRARY_PATH.
  • Restoring a checkpoint does not change secrets: they are stored apart from the computer's disk.
  • Settings, Secret key shows the app's key for Playcode services, PLAYCODE_SECRET_KEY. It is already in the app's environment. Copy it only for a server of your own, and choose Rotate if it leaks: the app restarts on the new key.
  • A static site has no server, so it cannot keep a secret: everything in its code reaches the visitor's browser.