Copy your .env values into Vercel's Environment Variables for Production and Preview, keep secret keys off the browser, and redeploy so they take effect.
Move the keys from my .env file into Vercel production
How it works
- Read your local .env file: Vovy lists every variable in your .env and sorts them into public ones (like VITE_ or NEXT_PUBLIC_ names, which ship to the browser) and secret ones that must stay on the server.
- Flag secrets in the wrong place: If a secret key like a Stripe sk_live key has a VITE_ prefix, anyone can read it in the browser. Vovy warns you in a card before anything goes to production.
- Open Environment Variables in Vercel: Vovy opens your project's Settings, then Environment Variables, and pastes each key and value, choosing Production, Preview, or both.
- Redeploy so the keys load: Vercel only applies new variables to new deployments. Vovy asks, then clicks Redeploy on your latest production deployment.
- Confirm the app reads them: Vovy opens your live site and checks the console for errors like "Invalid API key" or undefined values, then shows a table of what's set where.
What you provide
- Your .env file
- Access to your Vercel project
What you get
- All keys set in Production and Preview
- Warnings for any exposed secrets
- A redeployed app using the new values
- A table of every variable and where it lives
FAQ
I added the variable but the app still says it's missing. Why?
Environment variables only apply to deployments made after you add them. Redeploy, and it will pick them up.
Should I commit my .env file to GitHub?
No. Keep .env in your .gitignore and store the values in Vercel and a password manager like 1Password.
What's the difference between Production and Preview?
Production is your live site. Preview is every test deployment from other branches, so you can use test keys there and live keys in production.
Related tasks
All tasks