Public (VITE_*)
Visible to client code. For non-secret values: API base URLs, public keys (Stripe publishable, PostHog public).
Server-only
Available only in Convex actions and the build pipeline. For secrets: API keys, webhook signing secrets, service tokens.
Setting
- Dashboard
- CLI
- API
Settings → Environments → [env] → Variables → Add.
Reading
In Convex code:Rotation
For a single secret:1
Get a new value from the provider
e.g., generate a new Stripe API key.
2
Add the new value alongside the old
Use a temp name like
STRIPE_SECRET_KEY_NEW.3
Deploy code that reads the new value
Either rename or use a fallback pattern.
4
Revoke the old value
At the provider.
5
Remove the old name
Cleanup.
Common variables
Related
Secrets
Secret-store mechanics.
Secrets management
Best practices.
Environments
Per-env scoping.
