---
title: Environment variables
description: Inject configuration and secrets into your build and your running app.
---

Environment variables live under **Settings → Secrets**. They are injected into your build,
your running app, or both.

## Adding a variable

:::steps

1. **Open Settings → Secrets** and choose **Add Variable**.

2. **Give it a name and a value**

   Names are conventionally uppercase with underscores, e.g. `STRIPE_API_KEY`.

3. **Mark it as a secret if it is one**

   Turn on **Secret** for anything credential-like. Secret values are redacted in the
   variable list and kept out of build logs.

4. **Trigger a build**

   Variables are injected at build and deploy time, so an existing deployment does not pick
   up a change until it is rebuilt.

:::

## Where a variable is available

Under **Advanced**, each variable has a scope:

| Scope            | Available                                             |
| ---------------- | ----------------------------------------------------- |
| **Always**       | While building _and_ in the running app. The default. |
| **Build only**   | Only while your app is being built                    |
| **Runtime only** | Only in the deployed running app                      |

Use **Build only** for things needed to compile — a private registry token, for instance — so
they never reach the running process. Use **Runtime only** for values the build has no
business seeing.

> [!WARNING]
> On a static project there is no running process, so a **Runtime only** variable is never
> injected. The dashboard flags this when it applies.
