> ## Documentation Index
> Fetch the complete documentation index at: https://vlyai-1c28d863.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Environment variables

> Setting, reading, and rotating environment variables. Per-environment scoping.

Two kinds of env vars:

<CardGroup cols={2}>
  <Card title="Public (`VITE_*`)" icon="eye">
    Visible to client code. For non-secret values: API base URLs, public keys (Stripe publishable, PostHog public).
  </Card>

  <Card title="Server-only" icon="eye-off">
    Available only in Convex actions and the build pipeline. For secrets: API keys, webhook signing secrets, service tokens.
  </Card>
</CardGroup>

## Setting

<Tabs>
  <Tab title="Dashboard">
    Settings → Environments → \[env] → Variables → Add.
  </Tab>

  <Tab title="CLI">
    ```bash theme={null}
    vly env set RESEND_API_KEY re_... --env production
    vly env set VITE_PUBLIC_KEY pk_... --env production
    ```
  </Tab>

  <Tab title="API">
    `POST /v1/projects/{id}/env` — see [API reference](/api-reference/introduction).
  </Tab>
</Tabs>

## Reading

In Convex code:

```typescript theme={null}
process.env.RESEND_API_KEY   // server-only
import.meta.env.VITE_PUBLIC_KEY   // client-visible
```

## Rotation

For a single secret:

<Steps>
  <Step title="Get a new value from the provider">
    e.g., generate a new Stripe API key.
  </Step>

  <Step title="Add the new value alongside the old">
    Use a temp name like `STRIPE_SECRET_KEY_NEW`.
  </Step>

  <Step title="Deploy code that reads the new value">
    Either rename or use a fallback pattern.
  </Step>

  <Step title="Revoke the old value">
    At the provider.
  </Step>

  <Step title="Remove the old name">
    Cleanup.
  </Step>
</Steps>

For atomic rotation (no overlap), use a brief downtime window during low traffic.

## Common variables

| Variable | Purpose |
| - | - |
| `STRIPE_SECRET_KEY`, `STRIPE_WEBHOOK_SECRET` | Stripe |
| `RESEND_API_KEY` | Resend email |
| `OPENAI_API_KEY` | OpenAI |
| `ANTHROPIC_API_KEY` | Anthropic |
| `GITHUB_WEBHOOK_SECRET` | GitHub webhook verification |
| `APP_URL` | The app's base URL (used for OAuth redirects, email links) |

## Related

<CardGroup cols={3}>
  <Card title="Secrets" icon="lock" href="/deployment/secrets">
    Secret-store mechanics.
  </Card>

  <Card title="Secrets management" icon="key" href="/security/secrets-management">
    Best practices.
  </Card>

  <Card title="Environments" icon="layers" href="/deployment/environments">
    Per-env scoping.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.