Skip to main content
Two kinds of env vars:

Public (VITE_*)

Visible to client code. For non-secret values: API base URLs, public keys (Stripe publishable, PostHog public).

Server-only

Available only in Convex actions and the build pipeline. For secrets: API keys, webhook signing secrets, service tokens.

Setting

Settings → Environments → [env] → Variables → Add.

Reading

In Convex code:

Rotation

For a single secret:
1

Get a new value from the provider

e.g., generate a new Stripe API key.
2

Add the new value alongside the old

Use a temp name like STRIPE_SECRET_KEY_NEW.
3

Deploy code that reads the new value

Either rename or use a fallback pattern.
4

Revoke the old value

At the provider.
5

Remove the old name

Cleanup.
For atomic rotation (no overlap), use a brief downtime window during low traffic.

Common variables

Secrets

Secret-store mechanics.

Secrets management

Best practices.

Environments

Per-env scoping.
Last modified on April 18, 2026