Skip to main content
Environment variables and secrets let your app use sensitive values — like a Stripe API key — without writing them into your code. You set them per app in the app’s settings, and your published app reads them at runtime on Cloudflare Workers.
Never hard-code secrets directly in your code. API keys, tokens, and passwords belong in environment secrets, not in component files or API routes.

What to Store as Secrets

Use environment secrets for any value that’s sensitive or that changes between environments:
  • API keys — Stripe secret keys, webhook signing secrets, third-party service keys
  • Tokens — access tokens for external APIs
  • Configuration — values you don’t want committed into your codebase
Non-sensitive, public configuration can live in your code, but anything secret should always go through app settings.

Where to Set Them

Environment variables and secrets are managed per app in the app’s settings. Each app you build has its own set — they aren’t shared between apps.
1

Open your project's settings

Go to the settings for the app you’re building.
2

Open Environment

Select Environment to see the app’s environment variables and secrets.
3

Add a key and value

Enter the name (for example, STRIPE_SECRET_KEY) and paste its value, marking it as a secret if it’s sensitive. Use the exact name your app’s code reads.
4

Save

Save your changes. Your secret is stored securely and applied to your app the next time you publish.
Secrets you set apply to your published app — the preview doesn’t read them. If you add or change a secret after publishing, it takes effect the next time you publish. See Deploying Your App.

Finding the Secrets Your App Needs

Fabricate’s agent can’t set secrets for you or see their values. When you ask for an integration that needs credentials — payments, an external API, or anything similar — the code it writes reads each value by name, and your job is to supply the values in app settings. For example, Stripe payment code typically reads keys such as STRIPE_SECRET_KEY and STRIPE_WEBHOOK_SECRET. Check the exact names in the Code view, then set each one in Environment.
If your app errors after adding an integration, check that every secret your code reads is set and spelled exactly right, and that you’ve published since adding it. A missing or misnamed key is the most common cause.

How Your App Uses Them

Fabricate-generated apps run their backend on Cloudflare Workers. Secrets you set are exposed to your published app’s server code at runtime, so its API routes can read them without the values ever appearing in your source code. The preview runs without them, so a feature that needs a secret only works in your published app.

Security Best Practices

  • Never hard-code secrets. Keep keys out of components, API routes, and anything that could end up in version control.
  • Use test keys while building. For services like Stripe, use test-mode keys during development and switch to live keys only when you go to production.
  • Keep secrets per app. Don’t reuse one app’s production keys in another app.
  • Rotate if exposed. If a secret is ever leaked or pasted somewhere public, revoke it at the provider and set a fresh value.
  • Mind GitHub. If you push your code to GitHub, secrets stay in app settings — they are not committed — so your repository never contains them.

Frequently Asked Questions

No. Secrets live in app settings, not in your source files. Downloading your code or pushing it to GitHub does not include them.
Yes. Secrets set in app settings persist across redeploys. If you change a secret, the live app uses the new value from your next publish.
Each app has one set of secrets, and they apply to your published app. A common pattern is to publish with a service’s test keys first, then switch to live keys and republish when you’re ready for real use.
Check the code in the Code view for the names it reads, then add each one in your app’s settings under Environment.
The feature that depends on it will fail — and it always fails in the preview, which never has secrets. Add the missing secret, confirm the name matches exactly, and publish again.

Payments

What to know before adding Stripe — and the keys it needs.

Deploying Your App

Publish your app and apply your secrets.