Platform Environment Variables
Settings → Environment Variables answers one question: which environment-variable names can platform configuration read? It is a read-only inventory - values are never shown anywhere, and nothing is edited here.
What you see
- All discovered names - every environment-variable name reported by the running processes, each with a scope badge: API, Worker, or API + Worker.
- API process - the names visible to the API server.
- Workers - the names visible to each worker, listed per worker.
The scope matters: a secret backend's settings are resolved by both the API and the workers, so a name it reads must be set on both.
Where an environment variable can be used
Only platform configuration that platform admins manage can read an environment variable, with {{ env('NAME') }} or {{ env('NAME', 'fallback') }}:
- secret backend settings (for example the backend's bootstrap
token) - inventory provider settings (the provider
token_ref)
Flows, variables, devices, notifications, and git and file repositories are organization content, and they cannot read the platform's environment: it holds platform credentials. Store a value an organization needs as a secret and reference it with {{ secret('backend://path/key') }}, or as a variable when it is not sensitive. See Platform-only references for the full rule.
What this page is not
- It does not show values - by design, the only protection an environment variable gets in the UI is that its value is never displayed.
- It is not where you define values. Environment variables are set on the deployment itself (compose files, container environment) by whoever operates the platform.
- It is not the platform's own configuration reference. Hegemony's
HEGEMONY_-prefixed settings are documented separately in the environment variable reference.
This page requires the admin role.