Environment variables and secrets
Give an Aozumi app its API keys and settings. Values are encrypted, never shown again after saving, scoped to one environment, and can be imported from a .env file.
Add variables
The launch plan lists the variable names Aozumi found in your repository, for example in .env.example. Add a value for each in setup, or later from the app's settings. Aozumi encrypts each value before storing it.
After you save a value, Aozumi shows only its name. Values never appear again in the console, the API, logs or success messages, so keep a secure copy elsewhere.
Name rules
- Use uppercase letters, numbers and underscores. A name cannot begin with a number.
- Names beginning with
SHIPLET_are reserved for Aozumi's own protection. - Each value must be smaller than 32 KB.
PORTis set by Aozumi for server apps; listen on it instead of a fixed port.
Import a .env file
Use Import from .env in an environment's settings to add many variables at once. The file must be UTF-8, up to 256 KB and 200 variables. Aozumi checks names and limits before saving, and the preview shows names without values.
# Example only. Never commit real values.
API_BASE_URL=https://api.example.com
STRIPE_SECRET_KEY=your-stripe-key
PUBLIC_SITE_NAME=Team tools
Per environment
Production, staging and preview environments keep their own variables. Pull request previews never receive Production secrets; add only preview-safe values to them. See pull request previews.
The inspection also flags an .env.example that looks like it contains a real secret. If it does, move the value into Aozumi and rotate it.
Apply changes
A running release keeps the values it started with. Deploy again after changing variables so the app picks them up. The plan lists any required variable that is still missing and shows the app as not ready to deploy until it is set.
Agents can set values too, with the MCP secrets tool. See Connect an AI agent.
Questions
- Can I see a secret's value after saving it in Aozumi?
- No. Aozumi lists variable names only. Keep your own secure copy of each value; to change one, save a new value under the same name.
- Do preview deployments get my production secrets?
- No. Each environment has its own variables, and pull request previews never receive Production secrets. Add preview-safe values to the preview environment separately.
- Can an AI agent set environment variables?
- Yes. The MCP secrets tool stores encrypted values for an app. The agent sends the values; Aozumi returns only the names it stored.
Checked against the product on .