Skip to main content
Declare environment variables in your manifest, store secrets locally, and Runtime injects them at deploy time.

How it works

Secrets are never stored in Runtime’s database. Values pass directly from your machine to Fly.io.

Declaring environment variables

Define env vars in runtm.yaml:

Field reference

Managing secrets

Set a secret

Secrets are stored in .env.local in your project directory.

List secrets

Get / remove

Security

Automatic protection

.env.local is automatically added to both .gitignore and .cursorignore:
This means:
  • Secrets are never committed to git
  • AI assistants cannot read secret values

Log redaction

Secrets marked secret: true appear as [REDACTED] in logs:

Connections

Group related env vars as named connections:
Connections help organize which env vars belong together.

Using in code

Or with Pydantic:

Troubleshooting

Set the missing variable:
Secrets can’t have defaults. Remove the default field:
Redeploy after changing secrets: