Vovy checks your variable names, prefixes and where they are read, then fixes the setup so the right values reach the right place and secrets stay secret.
My API key shows as undefined in my app, fix my env variables
How it works
- Find where the value is read: Vovy searches your code for the variable, like import.meta.env.VITE_API_URL or process.env.NEXT_PUBLIC_URL, and notes whether it runs in the browser or server.
- Check the prefix rules: Browser code only sees variables starting with VITE_ in Vite or NEXT_PUBLIC_ in Next.js. Anything else is undefined there by design.
- Check your .env file: It checks the file name, .env or .env.local, for typos, quotes and spaces, and restarts the dev server since values load only at startup.
- Flag any exposed secret: If a secret key has a public prefix, Vovy warns you that it ships to every visitor and moves the call to the server instead.
- Sync to Vercel and redeploy: It adds any missing names to Vercel Environment Variables and triggers a redeploy, because public values are baked in at build time.
What you provide
- Your project open in Cursor
- The keys you want to use
What you get
- Variables that load correctly
- Prefix rules explained
- Exposed secrets flagged
- Vercel env in sync
FAQ
Why can't I just add NEXT_PUBLIC_ to my secret key?
Then anyone can read it in your site's JavaScript. Secret keys, like Stripe secret or OpenAI keys, must only be used in server code.
I changed the value in Vercel. Why is it still old?
Variables are read at build time for front-end code. You need a new deployment for the change to show.
Should .env be in GitHub?
No. Keep .env in .gitignore and share a .env.example with the names only.
Related tasks
All tasks