DocsBuild and deploy
Environment variables
Settings and secrets for your app: how to add them, when they apply, which ones are set for you, who sees their values, and the limits.
Use with AI
Environment variables hold what should not be in your code: database addresses, API keys, settings that differ between apps. Your app reads them from process.env. They are stored encrypted.
Add a variable
Section titled “Add a variable”Open Variables, enter a Key and a Value and choose Add.
To add many at once, choose Bulk edit and write one KEY=value per line. You can paste the content of a .env file. Lines you remove are deleted when you save.
When a change applies
Section titled “When a change applies”A saved variable reaches the app with the next deployment. After a change, the app shows a notice with Redeploy now: it puts the current version online again with the new values.
Where they are available
Section titled “Where they are available”| Where | Available |
|---|---|
| The running app | Yes |
| Deploy commands | Yes |
| Install and build | Only the ones with Build turned on |
During the build
Section titled “During the build”A variable is not set while the app is installed and built, unless you turn on Build next to it. Turn it on for what the install or the build really needs:
- a token for a private package, read by your
.npmrc - a value your build puts into the built files
Leave it off for everything else, so your build is given no secret it does not need.
A variable with Build on is set for the install and the build commands only while they run. It is not stored in the built image.
After you turn Build on or off, or change a variable that has it on, the next deployment builds the app again.
A name is made of capital letters, digits and underscores, and does not start with a digit: DATABASE_URL, STRIPE_KEY, MAX_ITEMS.
Set for you
Section titled “Set for you”These are set for every app. You cannot change or remove them:
| Variable | Value |
|---|---|
PORT |
The port from your build settings, 3000 unless you change it |
NODE_ENV |
production |
APP_URL |
The address of your app, with https:// |
Names that start with PLATFORM_ are kept for the platform as well.
Who sees the values
Section titled “Who sees the values”| Role | Can set variables | Can see values |
|---|---|---|
| Owner | Yes | Yes |
| Admin | Yes | Yes |
| Member | Yes | No |
See Teams for the roles.
Limits
Section titled “Limits”| Limit | |
|---|---|
| Variables for one app | 200 |
| One value | 32 KB |
| All names and values together | 256 KB |
A .env file
Section titled “A .env file”A .env file that is not committed does not exist on the platform, and it should not be committed. Add its content under Variables instead. A package like dotenv does no harm: it finds no file and the variables are already set.
© 2026 Orbit