Build & run
Environment variables and secrets
Configuration for a project, encrypted at rest on your own computer, never sent anywhere.
A project’s Environment tab is where its own configuration and secrets live, such as API keys, database URLs, feature flags, anything the project itself reads from process.env.
Adding a variable
Click Add variable, give it a name and value, and mark it as a secret if it’s sensitive (secrets are masked by default in the list; reveal one individually with the eye icon, or copy it directly without ever showing it on screen).
“N variables detected”
When a project has a .env.example-style file, FLY8HT reads the variable names it lists (never any values that happen to be in it) and shows which ones are already configured versus still missing. A likely-secret name (containing “key,” “token,” “password,” and so on) is pre-marked as a secret when you add it from that list, and you can always change it.
How this is actually stored
Every value is encrypted at rest, using your operating system’s own secure storage (Keychain on macOS, Credential Manager on Windows). Values are never stored as plain text on disk and never sent to a server anywhere. Values are also stripped from every build and runtime log line before they’re shown or saved, regardless of whether you marked them as secret.
If Docker isn’t available and a build runs as a local process instead, you’ll see a real warning: reduced isolation means the project’s own code can technically read these values while it builds or runs, so only build repositories you trust in that mode.
Related
Something wrong or unclear on this page? Tell us