Reporch IDE
Attach environment variables
Register workspace variables, choose scope and target, and pass only the required values to a deployment.
Overview
Register environment variables in workspace settings, then select the keys for a new deployment. Each variable has a key, value, applicable scope or target, and secret setting. Never store API keys or database passwords in source, MDX, or Git.
Before you start
- List the exact key names read by the application.
- Separate values for development, preview, and production targets.
- Distinguish browser-visible public configuration from server-only secrets.
- Use
.env.exampleonly for key names; do not commit real values.
Steps
1. Open workspace settings
Open Environment Variables for the workspace that will be deployed. Do not assume variables in another workspace are shared automatically.
2. Enter key and value
Match the application's key exactly, including case, and register its value. Check for unintended leading or trailing spaces and quotes.
3. Choose secret and scope
Mark sensitive values as secret. Select only the scopes and targets that need the value.
4. Open a new deployment
Go to Deployments → New Deployment and expand Environment Variables. Confirm that the key, scope, and target appear as expected.
5. Select required keys
Check only what this application uses. Distinguish similarly named development and production values by target.
6. Verify after deployment
Run the deployment and inspect logs for missing-variable errors. Remove debug code that prints actual secret values.
Naming and value rules
- Names are case-sensitive:
DATABASE_URLanddatabase_urlare different keys. - For multiline certificates or private keys, preserve the format accepted by the input instead of adding arbitrary
\nescapes. - Framework prefixes such as
NEXT_PUBLIC_orVITE_can place values in client bundles; never use them for secrets. - After rotating a value, determine whether a new deployment is required. Existing deployments do not necessarily change automatically.
Expected result
- Only selected variables reach the new deployment environment.
- The application reads the same key with different values per environment rather than hardcoding configuration.
- Secrets do not appear in docs, Git, or normal logs.
Troubleshooting
- List is empty: Register variables in the current workspace first.
- Undefined or missing: Check spelling, case, selection, and target.
- Works locally but not in deployment: Compare local
.envwith the keys selected for deployment. - Old value remains: Create a deployment after the update and verify its Deployment ID.
- Secret appears in logs: Revoke and rotate it immediately, then remove the logging code.