Configuration
Environment Variables
Workspace key/value config and secrets referenced as env.* in Liquid and path bindings.
Environment variables are workspace key/value pairs for shared config and secrets. Reference them as env.KEY in Liquid templates and path bindings.
Open Configuration → Environment Variables to manage them.
Store secrets in environment variables and reference them as
env.KEY. Do not hardcode API keys, tokens, or passwords in agents, templates, APIs, or MCP settings.When to use
- Store API keys, tokens, and shared config once instead of pasting them into agents, APIs, or MCP settings
- Mark sensitive values as Secret so they are masked in the UI where supported
- Prefer
env.*over hardcoding credentials in schemas, templates, or connected-service configs
Create environment variables
Add a key/value pair:
| Setting | What it does |
|---|---|
| Key | Name used as env.KEY. Letters, digits, and underscores; must start with a letter or _. Reserved names like env, global, this, and args are not allowed. |
| Value | The stored string (optional) |
| Secret | Marks the value as sensitive so it is masked in the UI where supported |
Reference workspace env vars as env.MY_KEY in Liquid and in path bindings.
Deleting an env var is permanent — check anything that references it first.
How to reference them
| Context | Syntax |
|---|---|
| Liquid text fields | {{ env.API_KEY }} |
| Path bindings on structured fields | env.API_KEY (no {{ }}) |
For Liquid syntax, path namespaces (args, pipe, session, and so on), and workflow Set Variables, see Variables.
Limits
- Env keys must match the naming rules above and cannot use reserved keywords.
- Prefer Secret env vars for credentials.
- Env vars are workspace resources; named workflow variables (
Set Variables/Update Variables) are run-scoped and separate.