Variables and secrets

Download all docs

Store project configuration and credentials safely, attach shared variables, and distinguish them from source Values.

Variables are runtime configuration. Use them for API keys, database URLs, tokens, and settings that differ between environments. Treat every variable value as secret: do not put it in source, prompts, Chat, Design Docs, task descriptions, table rows, logs, or published examples.

Project variables

Open a project's Variables tab to create configuration used only by that project. In local mode, adding a variable writes its value to the project's protected dotenv file and writes only a placeholder to .env.example. The placeholder can be committed; the value must not be committed. Start octonode serve before editing local variables in Studio.

Project workflows receive only the variables configured for that project. A generated service may map constructor dependencies such as apiUrl to environment keys such as API_URL; the secret value remains configuration and is never copied into generated TypeScript.

Shared workspace variables

Open Variables in the left rail to manage reusable values in the active personal, team, or organization scope. Then open a project's Variables tab and attach the shared variable by name. Attachment grants that project access without duplicating the value. Detaching it removes project access but keeps the shared variable for other attached projects.

Use the narrowest useful scope. Workspace members and project code are part of the workspace trust boundary, so do not attach a credential to a project whose code or plugins should not receive it.

Redaction and rotation

Variable APIs return redacted values. Run records also redact declared secrets and known secret values before persistence. Project exports omit dotenv files and secret values. These controls reduce accidental disclosure; trusted project code can still read a variable intentionally attached to it.

Saving the same key with a new value rotates it atomically for new work. Existing processes may keep the environment with which they started, so open a new terminal or restart the relevant process after rotation. Removing a variable can break workflows and integrations that reference its name.

Variables are not Values

The project Values tab represents TypeScript const declarations. Values are source-backed, reviewable, and may be committed to Git. Use them for non-secret defaults, labels, thresholds, and JSON-safe fixed inputs. Use Variables for configuration and secrets. Use Data tables for durable records that change while workflows run.

NeedUse
Secret or environment-specific configurationVariables
Non-secret constant owned by sourceValues
Durable mutable runtime recordsData tables