← All blocks
Docs page with nav tree and table of contents
docs-page · sidebar-article-toc · docs-layout-sidebar-toc
npx shadcn@latest add @plus-ui/docs-layout-sidebar-tocDefault content
{
"labels": {
"nav": "Documentation",
"openMenu": "Docs menu",
"onThisPage": "On this page",
"previous": "Previous",
"next": "Next",
"feedbackQuestion": "Was this page helpful?",
"yes": "Yes",
"no": "No",
"thanks": "Thanks. Every response goes to the docs team.",
"copy": "Copy",
"copied": "Copied"
},
"nav": [
{
"title": "Getting started",
"items": [
{
"label": "Introduction",
"href": "#"
},
{
"label": "Quickstart",
"href": "#"
},
{
"label": "Install the CLI",
"href": "#"
},
{
"label": "rivetlane.toml",
"href": "#"
}
]
},
{
"title": "Deploying",
"items": [
{
"label": "Git deploys",
"href": "#"
},
{
"label": "Preview environments",
"href": "#"
},
{
"label": "Environment variables",
"href": "#"
},
{
"label": "Custom domains",
"href": "#"
},
{
"label": "Rollbacks",
"href": "#"
}
]
},
{
"title": "Reference",
"items": [
{
"label": "CLI reference",
"href": "#"
},
{
"label": "REST API",
"href": "#"
},
{
"label": "Build images",
"href": "#"
},
{
"label": "Upgrading to v5",
"href": "#",
"badge": "New"
}
]
}
],
"current": "Environment variables",
"breadcrumbs": [
{
"label": "Docs",
"href": "#"
},
{
"label": "Deploying",
"href": "#"
},
{
"label": "Environment variables",
"href": "#"
}
],
"title": "Environment variables",
"lead": "Set configuration and secrets per environment. Rivetlane injects them at build time and at runtime, and never writes secret values to build logs.",
"meta": "Updated Oct 6, 2026 · 6 min read",
"body": [
{
"type": "heading",
"level": 2,
"text": "Scopes"
},
{
"type": "paragraph",
"text": "Every variable belongs to one or more scopes. A deploy reads the scope that matches its target, so the same key can hold a different value in each."
},
{
"type": "list",
"ordered": false,
"items": [
"`production` — deploys made with `rivet deploy --prod` or merged to your production branch.",
"`preview` — every preview environment, one per branch or pull request.",
"`development` — values written to `.env.local` by `rivet env pull`."
]
},
{
"type": "heading",
"level": 2,
"text": "Set a variable"
},
{
"type": "paragraph",
"text": "Use `rivet env set` from a linked project directory. Pass `--secret` for credentials: the value is encrypted at rest, masked in logs and cannot be read back from the dashboard."
},
{
"type": "code",
"language": "shell",
"label": "Terminal",
"code": "$ rivet env set DATABASE_URL \"postgres://[email protected]:5432/storefront\" --env production\n✓ Set DATABASE_URL for production (storefront)\n$ rivet env set TALLYBIRD_SECRET_KEY --env production,preview --secret\n? Value: ••••••••••••••••\n✓ Set TALLYBIRD_SECRET_KEY for production, preview (storefront) · secret"
},
{
"type": "callout",
"tone": "tip",
"title": "Changes apply on the next deploy",
"text": "Running deploys keep the values they started with. Run `rivet deploy --prod` to pick up a change without pushing a commit."
},
{
"type": "heading",
"level": 3,
"text": "Defaults in rivetlane.toml"
},
{
"type": "paragraph",
"text": "Non-secret defaults can live in the repository, next to the code that reads them. Values under `[env.preview]` override `[env]` for preview deploys only."
},
{
"type": "code",
"language": "toml",
"label": "rivetlane.toml",
"code": "[env]\nNODE_ENV = \"production\"\nLOG_LEVEL = \"info\"\n\n[env.preview]\nLOG_LEVEL = \"debug\""
},
{
"type": "callout",
"tone": "warning",
"title": "Keep secrets out of the repo",
"text": "`rivetlane.toml` is readable by anyone with access to the repository. A key that looks like a credential fails the build with `E_SECRET_IN_CONFIG`."
},
{
"type": "heading",
"level": 2,
"text": "Build time and runtime"
},
{
"type": "paragraph",
"text": "Variables are available to your build command and to the running app. Keys prefixed with `PUBLIC_` are also inlined into client bundles, so treat them as public."
},
{
"type": "callout",
"tone": "note",
"text": "Changing a `PUBLIC_` variable needs a fresh build. `rivet deploy --prod --force` skips the build cache; a plain redeploy reuses the old bundle."
},
{
"type": "heading",
"level": 2,
"text": "Pull variables locally"
},
{
"type": "paragraph",
"text": "Write the `development` scope to `.env.local` so local runs match your deploys. Secrets are included only for members with the Developer role or higher."
},
{
"type": "code",
"language": "shell",
"label": "Terminal",
"code": "$ rivet env pull --env development\n✓ Wrote 7 variables to .env.local (2 secrets)"
},
{
"type": "heading",
"level": 2,
"text": "Precedence"
},
{
"type": "paragraph",
"text": "When the same key is defined in more than one place, the first match wins:"
},
{
"type": "list",
"ordered": true,
"items": [
"A value set with `rivet env set` for the deploy's scope.",
"The `[env.<scope>]` table in `rivetlane.toml`.",
"The `[env]` table in `rivetlane.toml`."
]
}
],
"previous": {
"label": "Preview environments",
"href": "#"
},
"next": {
"label": "Custom domains",
"href": "#"
},
"edit": {
"label": "Edit this page",
"href": "#"
}
}