Reporch IDE

Attach environment variables

Register workspace variables, choose scope and target, and pass only the required values to a deployment.

Overview

Register environment variables in workspace settings, then select the keys for a new deployment. Each variable has a key, value, applicable scope or target, and secret setting. Never store API keys or database passwords in source, MDX, or Git.

Before you start

  • List the exact key names read by the application.
  • Separate values for development, preview, and production targets.
  • Distinguish browser-visible public configuration from server-only secrets.
  • Use .env.example only for key names; do not commit real values.

Steps

1. Open workspace settings

Open Environment Variables for the workspace that will be deployed. Do not assume variables in another workspace are shared automatically.

2. Enter key and value

Match the application's key exactly, including case, and register its value. Check for unintended leading or trailing spaces and quotes.

3. Choose secret and scope

Mark sensitive values as secret. Select only the scopes and targets that need the value.

4. Open a new deployment

Go to Deployments → New Deployment and expand Environment Variables. Confirm that the key, scope, and target appear as expected.

5. Select required keys

Check only what this application uses. Distinguish similarly named development and production values by target.

6. Verify after deployment

Run the deployment and inspect logs for missing-variable errors. Remove debug code that prints actual secret values.

Naming and value rules

  • Names are case-sensitive: DATABASE_URL and database_url are different keys.
  • For multiline certificates or private keys, preserve the format accepted by the input instead of adding arbitrary \n escapes.
  • Framework prefixes such as NEXT_PUBLIC_ or VITE_ can place values in client bundles; never use them for secrets.
  • After rotating a value, determine whether a new deployment is required. Existing deployments do not necessarily change automatically.

Expected result

  • Only selected variables reach the new deployment environment.
  • The application reads the same key with different values per environment rather than hardcoding configuration.
  • Secrets do not appear in docs, Git, or normal logs.

Troubleshooting

  • List is empty: Register variables in the current workspace first.
  • Undefined or missing: Check spelling, case, selection, and target.
  • Works locally but not in deployment: Compare local .env with the keys selected for deployment.
  • Old value remains: Create a deployment after the update and verify its Deployment ID.
  • Secret appears in logs: Revoke and rotate it immediately, then remove the logging code.
Reporch Team